CYBERSEC-TP-RISK.AE1
Cybersecurity and Third-Party Risk
Learn to identify, assess, and mitigate cybersecurity risks posed by third-party vendors and suppliers.
- Practice in 17 Hands-On Labs — nothing to install
- 18 Interactive Lessons and 66 topics mapped to the official exam objectives
- 272 Practice Test Questions
Intermediate Self-paced · 1 year access 4.3/5 (105 Reviews)
17 Hands-On LiveLabs
Practice real IT tasks in guided environments.
- Real environments
- Auto-graded
- No installation
01 / Skills you'll get
What you will be able to do
- Identify and assess potential cybersecurity risks posed by third-party vendors and suppliers
- Conduct thorough due diligence on third-party vendors to evaluate their security practices and compliance with industry standards
- Use supply chain security best practices to prevent attacks and data breaches
- Take actions to ensure compliance with the relevant cybersecurity regulations and standards (e.g. GDPR, HIPAA, PCI DSS)
- Implement strategies based on cybersecurity frameworks such as NIST Cybersecurity Framework and ISO 27001
- Maintain a proactive cybersecurity posture and continuously improve risk management processes
Course Highlights
-
18 Structured Lessons Comprehensive coverage of core course objectives
-
17 Hands-On LiveLabs Interactive guided scenarios with instant evaluation
-
272 Practice Questions Assessment tests with detailed answer rationales
-
1 Year Full Access Self-paced learning accessible anytime on all devices
02 / Lessons & labs
See exactly what you will learn and practice
Lessons
18 Interactive Lessons · 66 topics01 Introduction 1 topics +
- Who Will Benefit Most from This Course?
02 What Is the Risk? 8 topics +
- The SolarWinds Supply‐Chain Attack
- The VGCA Supply‐Chain Attack
- The Zyxel Backdoor Attack
- Other Supply‐Chain Attacks
- Problem Scope
- Compliance Does Not Equal Security
- Third‐Party Breach Examples
- Conclusion
03 Cybersecurity Basics 5 topics · 3 LiveLab +
- Cybersecurity Basics for Third-Party Risk
- Cybersecurity Frameworks
- Due Care and Due Diligence
- Cybercrime and Cybersecurity
- Conclusion
3 LiveLab in this lesson — see the labs panel →
04 What the COVID‐19 Pandemic Did to Cybersecurity and Third‐Party Risk 3 topics · 1 LiveLab +
- The Pandemic Shutdown
- SolarWinds Attack Update
- Conclusion
1 LiveLab in this lesson — see the labs panel →
05 Third‐Party Risk Management 4 topics +
- Third‐Party Risk Management Frameworks
- The Cybersecurity and Third‐Party Risk Program Management
- The Kristina Conglomerate (KC) Enterprises
- Conclusion
06 Onboarding Due Diligence 3 topics +
- Intake
- Cybersecurity Third‐Party Intake
- Conclusion
07 Ongoing Due Diligence 8 topics · 2 LiveLab +
- Low‐Risk Vendor Ongoing Due Diligence
- Moderate‐Risk Vendor Ongoing Due Diligence
- High‐Risk Vendor Ongoing Due Diligence
- “Too Big to Care”
- A Note on Phishing
- Intake and Ongoing Cybersecurity Personnel
- Ransomware: A History and Future
- Conclusion
2 LiveLab in this lesson — see the labs panel →
08 On‐site Due Diligence 3 topics +
- On‐site Security Assessment
- On‐site Due Diligence and the Intake Process
- Conclusion
09 Continuous Monitoring 4 topics · 1 LiveLab +
- What Is Continuous Monitoring?
- Enhanced Continuous Monitoring
- Third‐Party Breaches and the Incident Process
- Conclusion
1 LiveLab in this lesson — see the labs panel →
10 Offboarding 2 topics · 1 LiveLab +
- Access to Systems, Data, and Facilities
- Conclusion
1 LiveLab in this lesson — see the labs panel →
11 Securing the Cloud 2 topics · 2 LiveLab +
- Why Is the Cloud So Risky?
- Conclusion
2 LiveLab in this lesson — see the labs panel →
12 Cybersecurity and Legal Protections 3 topics +
- Legal Terms and Protections
- Cybersecurity Terms and Conditions
- Conclusion
13 Software Due Diligence 7 topics · 3 LiveLab +
- The Secure Software Development Lifecycle
- On‐Premises Software
- Cloud Software
- Open Web Application Security Project Explained
- Open Source Software
- Mobile Software
- Conclusion
3 LiveLab in this lesson — see the labs panel →
14 Network Due Diligence 3 topics · 3 LiveLab +
- Third‐Party Connections
- Zero Trust for Third Parties
- Conclusion
3 LiveLab in this lesson — see the labs panel →
15 Offshore Third‐Party Cybersecurity Risk 4 topics · 1 LiveLab +
- Onboarding Offshore Vendors
- Country Risk
- KC's Country Risk
- Conclusion
1 LiveLab in this lesson — see the labs panel →
16 Transform to Predictive 5 topics +
- The Data
- Level Set
- A Mature to Predictive Approach
- The Predictive Approach at KC Enterprises
- Conclusion
17 Conclusion +
18 Appendix: Key Terms 1 topics +
- Glossary
Hands-On Labs Our edge
17 LiveLabs- Simulating the DoS Attack
- Performing a Phishing Attack
- Performing Local Privilege Escalation
- Establishing a VPN Connection
- Getting the TCP Settings and Information about the TCP Port
- Detecting a Phishing Site Using Netcraft
- Analyzing Malware
- Supplying Power to a SATA Drive
- Creating an Elastic Load Balancer
- Working with Amazon S3
- Attacking a Website Using XSS Injection
- Fuzzing Using OWASP ZAP
- Setting Up a Basic Web Server
- Studying CVSS Exercises with the CVSS Calculator
- Setting up a DMZ
- Enabling the TPM
- Using the Windows Firewall
03 / FAQs
Questions before you start
What is risk in cyber security? +
Who should take a course on Cybersecurity and Third-Party Risk? +
Individuals in various roles can benefit from this course, including:
- IT professionals
- Security analysts
- Risk managers
- Compliance officers
- Business leaders
How long does it take to complete the Cybersecurity and Third-Party Risk course? +
What is the difference between third-party risk and vendor risk management? +
- Third-party risk discusses all potential risks associated with external entities, including vendors, suppliers, contractors, and business partners.
- Vendor risk management is a specific subset of third-party risk management that focuses on assessing and mitigating risks related to vendors.
What types of organizations benefit most from third-party risk management? +
Organizations of all sizes and industries can benefit from third-party risk management. But it is especially important for:
- Large enterprises with complex supply chains
- Organizations in highly regulated industries industries
- Companies that rely heavily on third-party vendors
What are the types of third-party risk?+
Common types of third-party risk include:
- Operational risk
- Financial risk
- Reputational risk
- Legal risk
Can I pursue any cybersecurity risk management certification after taking this course?+
Yes, you can pursue third-party risk management certifications such as:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Risk Manager (CRM)
Learn to Mitigate Supply Chain Cyber Risks
Prepare yourself for the evolving threat landscape by learning to manage cybersecurity and third-party risks.
- 1 year of full access
- 17 LiveLab included
- Certificate of completion
No credit card required