Overview
This advanced e-learning program provides a practical, scenario-based approach to managing cyber and operational risks related to third parties using the FAIR™ Standard.
The course covers the complete TPRM lifecycle — third-party mapping, due diligence, contracting, onboarding, continuous monitoring, and periodic review. Participants learn to identify exposures, build risk scenarios, and quantify them financially using data-driven methods across various supplier contexts.
Who is this for?
- CISOs and Heads of Information Security
- Cybersecurity and risk analysts
- TPRM practitioners
- GRC consultants
- Procurement teams and vendor managers
- Technical auditors
What you'll learn
- Understand the cyber and operational risk challenges arising from third-party relationships
- Identify assets, threats, and loss events in third-party risk scenarios
- Build FAIR scenarios tailored to different supplier types
- Quantify third-party risks using estimation ranges and Monte Carlo simulations
- Integrate quantitative results into due diligence, contracting, and monitoring
- Communicate vendor risk exposure in financial terms for decision-making
Format & duration
Approximately 10 hours · Unlimited access for 3 months · Capstone project included
10 CPE credits awarded on completion.
Prerequisites
None required. A basic understanding of risk quantification with FAIR may be beneficial.