
Third-Party Cybersecurity Risk Assessment and Auditing
Preview locked — enroll to start watching.
Governance, Risk & Compliance
Third-Party Cybersecurity Risk Assessment and Auditing
Assess vendor risk. Test security controls. Report defensible conclusions.
by eSafeguards Consulting Inc. · all levels · specialized · 12–15 hours · Premium
Who this course is for: Beginners entering cybersecurity GRC; cybersecurity and GRC professionals; third-party and vendor risk analysts; internal and IT auditors; information security analysts; compliance and risk professionals; procurement and vendor-management professionals; privacy and data-protection professionals; business owners responsible for technology vendors; and consultants performing vendor risk assessments.
A practical, self-paced professional course covering the assessment and auditing of cybersecurity risks and controls associated with third-party technology service providers — from vendor intake and inherent-risk tiering through control testing, audit workpapers, findings, and remediation validation.
Progress from beginner to advanced as you assess and audit the cybersecurity risk of third-party technology providers. You will identify vendor risk, calculate inherent risk and tier vendors, scope risk-based assessments, run security questionnaires and vendor interviews, evaluate evidence and SOC 2 / ISO 27001 assurance, test controls with documented sampling, write defensible findings and audit workpapers, and validate remediation. The course is built around a single evolving case study — SecureOps Managed Services — and a persistent Assessment and Audit Workbench. A risk assessment identifies and evaluates cybersecurity exposure; an audit independently tests whether controls are appropriately designed and operating effectively; a compliance review evaluates adherence to specified requirements; and a questionnaire response alone is never sufficient evidence that a control operates effectively.
What you'll be able to do
- Explain how third parties create cybersecurity risk.
- Differentiate between a cybersecurity assessment, audit and compliance review.
- Collect vendor intake and business-context information.
- Calculate inherent risk and assign a vendor tier.
- Determine when a questionnaire, evidence review or formal audit is required.
- Scope a risk-based third-party cybersecurity assessment.
- Design and evaluate vendor security questions.
- Conduct a vendor clarification interview.
- Request and evaluate relevant cybersecurity evidence.
- Review SOC 2 reports and ISO 27001 certifications.
- Distinguish between missing evidence and a failed control.
- Evaluate control design and operating effectiveness.
- Develop a risk and control matrix.
- Write step-by-step cybersecurity audit procedures.
- Select and document audit samples.
- Test third-party cybersecurity controls.
- Document audit workpapers and exceptions.
- Rate risks and write defensible findings.
- Recommend approval, conditional approval, remediation, escalation, risk acceptance or rejection.
- Validate remediation and close findings.
- Prepare an executive assessment or audit report.
Course modules
Module 1: Third-Party Cybersecurity Risk Fundamentals
Level 1 — Foundation. Understand what a third party is, how technology vendors create cybersecurity risk, and the difference between a risk assessment, an audit, and a compliance review.
Module 2: Vendor Intake, Risk Tiering and Assessment Triggers
Level 1 — Foundation. Classify vendor information and access, calculate inherent risk, assign a vendor tier, and determine when a questionnaire, evidence review, or formal audit is required.
Module 3: Planning and Scoping the Cybersecurity Assessment
Level 2 — Practitioner. Define assessment objectives, scope, control domains, exclusions, and evidence requirements for a risk-based third-party cybersecurity assessment.
Module 4: Security Questionnaires and Vendor Interviews
Level 2 — Practitioner. Design clear, testable security questions, run a vendor clarification interview with professional skepticism, and document follow-up.
Module 5: Evidence and Independent Assurance Review
Level 2 — Practitioner. Evaluate evidence for sufficiency, reliability, and currency, and review SOC 2 and ISO 27001 assurance reports including scope, exceptions, and bridge letters.
Module 6: Risk Analysis, Findings and Assessment Decisions
Level 2 — Practitioner. Distinguish missing evidence from failed controls, rate risk, develop defensible findings, and recommend approval, remediation, risk acceptance, or rejection.
Module 7: Planning a Third-Party Cybersecurity Audit
Level 3 — Advanced Audit Practice. Plan a risk-based third-party cybersecurity audit: objective, criteria, scope, risk-and-control matrix, and engagement memorandum.
Module 8: Testing Third-Party Cybersecurity Controls
Level 3 — Advanced Audit Practice. Test control design and operating effectiveness using inquiry, inspection, observation, reperformance, and technical validation, with documented sampling.
Module 9: Audit Working Papers, Findings and Reporting
Level 3 — Advanced Audit Practice. Complete audit workpapers, develop findings (condition, criteria, cause, consequence), and prepare an executive audit report.
Module 10: Remediation Validation and Ongoing Assurance
Level 3 — Advanced Audit Practice. Validate remediation evidence, close or retest findings, and design an ongoing assurance and continuous-monitoring plan.
Course updates
Frequently asked questions
No. The course begins with fundamentals and progresses to advanced audit practice, so learners can start without previous vendor-risk or auditing experience.
Student reviews
Individual enrollment
Pay once and start learning right away — your purchase enrolls you instantly and grants full course access.
- 365 days access
- 0 lessons
- Certificate on completion
No lessons yet.



