Back to browse
Third-Party Cybersecurity Risk Assessment and Auditing

Third-Party Cybersecurity Risk Assessment and Auditing

Preview locked — enroll to start watching.

Governance, Risk & Compliance

Third-Party Cybersecurity Risk Assessment and Auditing

Assess vendor risk. Test security controls. Report defensible conclusions.

by eSafeguards Consulting Inc. · all levels · specialized · 12–15 hours · Premium

Who this course is for: Beginners entering cybersecurity GRC; cybersecurity and GRC professionals; third-party and vendor risk analysts; internal and IT auditors; information security analysts; compliance and risk professionals; procurement and vendor-management professionals; privacy and data-protection professionals; business owners responsible for technology vendors; and consultants performing vendor risk assessments.

A practical, self-paced professional course covering the assessment and auditing of cybersecurity risks and controls associated with third-party technology service providers — from vendor intake and inherent-risk tiering through control testing, audit workpapers, findings, and remediation validation.

Progress from beginner to advanced as you assess and audit the cybersecurity risk of third-party technology providers. You will identify vendor risk, calculate inherent risk and tier vendors, scope risk-based assessments, run security questionnaires and vendor interviews, evaluate evidence and SOC 2 / ISO 27001 assurance, test controls with documented sampling, write defensible findings and audit workpapers, and validate remediation. The course is built around a single evolving case study — SecureOps Managed Services — and a persistent Assessment and Audit Workbench. A risk assessment identifies and evaluates cybersecurity exposure; an audit independently tests whether controls are appropriately designed and operating effectively; a compliance review evaluates adherence to specified requirements; and a questionnaire response alone is never sufficient evidence that a control operates effectively.

What you'll be able to do

  • Explain how third parties create cybersecurity risk.
  • Differentiate between a cybersecurity assessment, audit and compliance review.
  • Collect vendor intake and business-context information.
  • Calculate inherent risk and assign a vendor tier.
  • Determine when a questionnaire, evidence review or formal audit is required.
  • Scope a risk-based third-party cybersecurity assessment.
  • Design and evaluate vendor security questions.
  • Conduct a vendor clarification interview.
  • Request and evaluate relevant cybersecurity evidence.
  • Review SOC 2 reports and ISO 27001 certifications.
  • Distinguish between missing evidence and a failed control.
  • Evaluate control design and operating effectiveness.
  • Develop a risk and control matrix.
  • Write step-by-step cybersecurity audit procedures.
  • Select and document audit samples.
  • Test third-party cybersecurity controls.
  • Document audit workpapers and exceptions.
  • Rate risks and write defensible findings.
  • Recommend approval, conditional approval, remediation, escalation, risk acceptance or rejection.
  • Validate remediation and close findings.
  • Prepare an executive assessment or audit report.

Course modules

Module 1: Third-Party Cybersecurity Risk Fundamentals

Level 1 — Foundation. Understand what a third party is, how technology vendors create cybersecurity risk, and the difference between a risk assessment, an audit, and a compliance review.

Module 2: Vendor Intake, Risk Tiering and Assessment Triggers

Level 1 — Foundation. Classify vendor information and access, calculate inherent risk, assign a vendor tier, and determine when a questionnaire, evidence review, or formal audit is required.

Module 3: Planning and Scoping the Cybersecurity Assessment

Level 2 — Practitioner. Define assessment objectives, scope, control domains, exclusions, and evidence requirements for a risk-based third-party cybersecurity assessment.

Module 4: Security Questionnaires and Vendor Interviews

Level 2 — Practitioner. Design clear, testable security questions, run a vendor clarification interview with professional skepticism, and document follow-up.

Module 5: Evidence and Independent Assurance Review

Level 2 — Practitioner. Evaluate evidence for sufficiency, reliability, and currency, and review SOC 2 and ISO 27001 assurance reports including scope, exceptions, and bridge letters.

Module 6: Risk Analysis, Findings and Assessment Decisions

Level 2 — Practitioner. Distinguish missing evidence from failed controls, rate risk, develop defensible findings, and recommend approval, remediation, risk acceptance, or rejection.

Module 7: Planning a Third-Party Cybersecurity Audit

Level 3 — Advanced Audit Practice. Plan a risk-based third-party cybersecurity audit: objective, criteria, scope, risk-and-control matrix, and engagement memorandum.

Module 8: Testing Third-Party Cybersecurity Controls

Level 3 — Advanced Audit Practice. Test control design and operating effectiveness using inquiry, inspection, observation, reperformance, and technical validation, with documented sampling.

Module 9: Audit Working Papers, Findings and Reporting

Level 3 — Advanced Audit Practice. Complete audit workpapers, develop findings (condition, criteria, cause, consequence), and prepare an executive audit report.

Module 10: Remediation Validation and Ongoing Assurance

Level 3 — Advanced Audit Practice. Validate remediation evidence, close or retest findings, and design an ongoing assurance and continuous-monitoring plan.

Course updates

Frequently asked questions

No. The course begins with fundamentals and progresses to advanced audit practice, so learners can start without previous vendor-risk or auditing experience.

Student reviews

0.0
(0 reviews)
Sign in and complete this course to leave a review.

No reviews yet. Be the first!

$120one-time

Individual enrollment

Pay once and start learning right away — your purchase enrolls you instantly and grants full course access.

Sign in to enroll
  • 365 days access
  • 0 lessons
  • Certificate on completion
14-day refund policy — see details

No lessons yet.

We use cookies to keep you signed in and to understand how the platform is used. See our Privacy Policy.