Terminology Index

Glossary

1801 terms

Open concept maps

Showing 417-448 of 1801 terms

C
32

Continuous Vendor Monitoring

Keeping watch on third-party vendors' security and risk on an ongoing basis, rather than only at onboarding, so that a vendor's deteriorating posture, breach, or new risk is detected while the relationship is active.

Vendor risk does not freeze after a one-time assessment at onboarding; a vendor can be breached, let controls lapse, or take on new fourth-party dependencies. Continuous vendor monitoring tracks vendors' security posture, news, and risk signals throughout the relationship, so emerging third-party risk is caught early. It is a key part of third-party risk management and reflects that supply-chain risk is dynamic.

Introduced in: Risk Management Fundamentals

Examples

  • Detecting that an active vendor suffered a breach and reassessing the risk.
  • Tracking a vendor's security ratings between annual reviews.
  • Catching new fourth-party dependencies a vendor has taken on.

No related terms linked yet.