Search
Courses, guides, templates, the Digital Trust Common Framework and threat intelligence. Type a course code, a control, an obligation or a phrase.
9 results.
-
Reading a SOC 2 Report: Opinion, Scope, Exceptions, CUECs and Subservice Organisations
A SOC 2 report can look clean while missing exactly what you
Included with Practitioner membership. Compare tiers
-
AI in Third-Party Risk: Questionnaires and Evidence
Vendor reviews pile up because questionnaires and SOC reports take hours to
Included with Practitioner membership. Compare tiers
-
Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification
Vendor risk changes between annual reviews. Monitor vendors continuously, catch expiring reports
Included with Executive Practitioner membership. Compare tiers
-
Fourth-Party and Concentration Risk
Your vendors' vendors can take you down. Map subprocessors and spot concentration
Included with Executive Practitioner membership. Compare tiers
-
Vendor Due Diligence Questionnaires: SIG, CAIQ, Custom and Scoring
Long questionnaires waste everyone's time and still miss the risk. Build
Included with Practitioner membership. Compare tiers
-
Building a Third-Party Risk Program: From Zero and At Scale
You can't review every vendor the same way. Build a third
Included with Practitioner membership. Compare tiers
-
Contracting for Risk: DPAs, BAAs, Security Schedules and Right to Audit
Contracts are the only leverage you have after signature. Know which clauses
Included with Practitioner membership. Compare tiers
-
Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations
Every SOC report hands you controls you're expected to run. Turn
Included with Practitioner membership. Compare tiers
-
HITRUST for HealthTech: Self-Assessment to Validated
HITRUST is often a customer requirement in healthcare. Move from self-assessment
Included with Executive Practitioner membership. Compare tiers