Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation.
Reduce supply chain cyber risk by turning third-party risk management into an operational program that connects procurement, legal, and security decisions. This book replaces checkbox assessments with a lifecycle approach you can apply from onboarding through offboarding, so vendor risk tiering, control mapping, and continuous monitoring drive clear outcomes.
You learn how to align supplier oversight with major obligations and guidance, including DORA, GDPR, Executive Order 14028, NIST C-SCRM, and ISO/IEC 27036. You also get practical methods for strengthening contracts and SLAs—covering audit rights, breach notification, liability, and security requirements that flow down to critical subcontractors.
From threat intelligence and security ratings to incident response playbooks for vendor and sub-vendor breaches, the book shows how to handle real signals, not just survey answers. Written by practitioners with deep experience in supply chain risk and offensive security, it also explains how SBOM standards and AI-assisted scoring can support scalable governance. By the end, you can build and mature an intelligence-driven TPRM program focused on measurable resilience.
This book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. Compliance teams and in-house counsel working with DORA, GDPR, HIPAA, and related requirements will also benefit. Basic familiarity with security principles and vendor management helps.
Les informations fournies dans la section « Synopsis » peuvent faire référence à une autre édition de ce titre.
Eric Richardson has had a distinguished technology career in roles from CISO/ to executive to volunteer AP Comp Sci teacher with over 30 years of experience specializing in the critical intersection of Cybersecurity, Artificial Intelligence, and Operational Risk. Currently serving as the Global Leader of Artificial Intelligence and Security Engineering at Cisco, he spearheads corporate-wide standards for secure AI implementation and evaluates complex architectures to ensure robust security controls. His deep technical expertise in AI is evidenced by his authorship of "Prompt Engineering: Hands-on guide to prompt engineering for AI interactions". Eric resides in Washington State with his Wife Stacie and his daughters Katie and Maddie. Eric possesses a Masters in Computer Science with a focus on cybersecurity Engineering as well as a MBA.
Filipi Pires is an internationally recognized cybersecurity leader, researcher, and global speaker specializing in adversary emulation, identity security, and offensive security operations. With over 15 years of experience in the cybersecurity industry, he has built a career at the intersection of technical research, product strategy, and community leadership, helping organizations understand, simulate, and defend against real-world cyber threats. He currently serves as Head of Technical Advocacy at SCYTHE, where he leads global initiatives focused on Breach & Attack Simulation (BAS) and Adversarial Emulation & Validation (AEV). In this role, Filipi works closely with enterprises, government organizations, and security teams worldwide to operationalize adversary simulation, validate defensive controls, and mature cyber resilience programs through realistic attack scenarios. Beyond his corporate role, Filipi is the Founder & Investor at CROSS-INTEL, a global cybersecurity consulting and market-expansion firm, and Advisor & Investor at Sherlockeye, an AI-driven OSINT intelligence platform designed to accelerate cyber investigations and threat intelligence operations. He serves as Organizer of BSides Porto, one of Europe's fastest-growing community cybersecurity conferences, and Director of the Red Team Village at DEF CON, one of the most respected offensive security communities in the world. He is also Senior Advisor at Raíces Cyber Academy and Founder of the Red Team Community across Brazil and Latin America, initiatives dedicated to developing the next generation of offensive security professionals. As an international conference speaker, Filipi has delivered technical presentations and research at many of the world's most prestigious cybersecurity events, including multiple editions of Black Hat USA, DEF CON, Black Hat Middle East & Africa, RSA Conference-related events, and numerous BSides conferences worldwide. His talks focus on identity-centric attack paths, cloud privilege escalation, supply-chain compromise, breach simulation, and real adversary tradecraft. He has been recognized among the Top 3% Most Active Security Speakers globally, reflecting both the volume and impact of his contributions to the industry. His industry recognitions include AWS Community Builder and Snyk Ambassador. He is also known globally as an advocate for hacking through his long-standing initiative “Hacking is NOT a Crime,” promoting responsible research, education, and collaboration across the cybersecurity ecosystem. Through his work spanning industry, research, education, and community leadership, Filipi Pires continues to advance adversary simulation practices, identity-focused security, and the global maturation of offensive cybersecurity capabilities.
Les informations fournies dans la section « A propos du livre » peuvent faire référence à une autre édition de ce titre.
Vendeur : BargainBookStores, Grand Rapids, MI, Etats-Unis
Paperback or Softback. Etat : New. TPRM-Driven Supply Chain Cybersecurity: Connecting TPRM and supply chain security for operational resilience. Book. N° de réf. du vendeur BBS-9781806708116
Quantité disponible : 5 disponible(s)
Vendeur : California Books, Miami, FL, Etats-Unis
Etat : New. N° de réf. du vendeur I-9781806708116
Quantité disponible : Plus de 20 disponibles
Vendeur : Grand Eagle Retail, Bensenville, IL, Etats-Unis
Paperback. Etat : new. Paperback. Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation.Key FeaturesDesign a lifecycle-based TPRM program that ties vendor decisions to cyber riskMap DORA, NIST C-SCRM, and ISO/IEC 27036 controls to audits and evidenceBuild contract clauses, SBOM requirements, and playbooks for third- and fourth-party breachesIncludes assessment templates, evidence checklists, and incident playbooks you can adaptBook DescriptionReduce supply chain cyber risk by turning third-party risk management into an operational program that connects procurement, legal, and security decisions. This book replaces checkbox assessments with a lifecycle approach you can apply from onboarding through offboarding, so vendor risk tiering, control mapping, and continuous monitoring drive clear outcomes.You learn how to align supplier oversight with major obligations and guidance, including DORA, GDPR, Executive Order 14028, NIST C-SCRM, and ISO/IEC 27036. You also get practical methods for strengthening contracts and SLAscovering audit rights, breach notification, liability, and security requirements that flow down to critical subcontractors.From threat intelligence and security ratings to incident response playbooks for vendor and sub-vendor breaches, the book shows how to handle real signals, not just survey answers. Written by practitioners with deep experience in supply chain risk and offensive security, it also explains how SBOM standards and AI-assisted scoring can support scalable governance. By the end, you can build and mature an intelligence-driven TPRM program focused on measurable resilience.What you will learnLearn how vendor ecosystems become attack pathsCategorize third- and fourth-party supply chain risksCreate risk tiers and segmentation based on business impactDesign a lifecycle workflow from onboarding to offboardingSelect controls using NIST and ISO supply chain guidanceTranslate DORA, GDPR, and EO 14028 duties into controlsPrepare evidence packs for audits and regulator questionsPlan continuous monitoring beyond annual questionnairesWho this book is forThis book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. Compliance teams and in-house counsel working with DORA, GDPR, HIPAA, and related requirements will also benefit. Basic familiarity with security principles and vendor management helps. Connect third-party risk management and supply chain cybersecurity. Build a lifecycle for vendor risk assessment, align with NIST C-SCRM, ISO 27036, DORA, and implement SBOM, monitoring, and vendor breach response. This item is printed on demand. Shipping may be from multiple locations in the US or from the UK, depending on stock availability. N° de réf. du vendeur 9781806708116
Quantité disponible : 1 disponible(s)
Vendeur : PBShop.store UK, Fairford, GLOS, Royaume-Uni
PAP. Etat : New. New Book. Shipped from UK. Established seller since 2000. N° de réf. du vendeur L2-9781806708116
Quantité disponible : Plus de 20 disponibles
Vendeur : PBShop.store US, Wood Dale, IL, Etats-Unis
PAP. Etat : New. New Book. Shipped from UK. Established seller since 2000. N° de réf. du vendeur L2-9781806708116
Quantité disponible : Plus de 20 disponibles
Vendeur : CitiRetail, Stevenage, Royaume-Uni
Paperback. Etat : new. Paperback. Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation.Key FeaturesDesign a lifecycle-based TPRM program that ties vendor decisions to cyber riskMap DORA, NIST C-SCRM, and ISO/IEC 27036 controls to audits and evidenceBuild contract clauses, SBOM requirements, and playbooks for third- and fourth-party breachesIncludes assessment templates, evidence checklists, and incident playbooks you can adaptBook DescriptionReduce supply chain cyber risk by turning third-party risk management into an operational program that connects procurement, legal, and security decisions. This book replaces checkbox assessments with a lifecycle approach you can apply from onboarding through offboarding, so vendor risk tiering, control mapping, and continuous monitoring drive clear outcomes.You learn how to align supplier oversight with major obligations and guidance, including DORA, GDPR, Executive Order 14028, NIST C-SCRM, and ISO/IEC 27036. You also get practical methods for strengthening contracts and SLAscovering audit rights, breach notification, liability, and security requirements that flow down to critical subcontractors.From threat intelligence and security ratings to incident response playbooks for vendor and sub-vendor breaches, the book shows how to handle real signals, not just survey answers. Written by practitioners with deep experience in supply chain risk and offensive security, it also explains how SBOM standards and AI-assisted scoring can support scalable governance. By the end, you can build and mature an intelligence-driven TPRM program focused on measurable resilience.What you will learnLearn how vendor ecosystems become attack pathsCategorize third- and fourth-party supply chain risksCreate risk tiers and segmentation based on business impactDesign a lifecycle workflow from onboarding to offboardingSelect controls using NIST and ISO supply chain guidanceTranslate DORA, GDPR, and EO 14028 duties into controlsPrepare evidence packs for audits and regulator questionsPlan continuous monitoring beyond annual questionnairesWho this book is forThis book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. Compliance teams and in-house counsel working with DORA, GDPR, HIPAA, and related requirements will also benefit. Basic familiarity with security principles and vendor management helps. Connect third-party risk management and supply chain cybersecurity. Build a lifecycle for vendor risk assessment, align with NIST C-SCRM, ISO 27036, DORA, and implement SBOM, monitoring, and vendor breach response. This item is printed on demand. Shipping may be from our UK warehouse or from our Australian or US warehouses, depending on stock availability. N° de réf. du vendeur 9781806708116
Quantité disponible : 1 disponible(s)
Vendeur : AussieBookSeller, Truganina, VIC, Australie
Paperback. Etat : new. Paperback. Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation.Key FeaturesDesign a lifecycle-based TPRM program that ties vendor decisions to cyber riskMap DORA, NIST C-SCRM, and ISO/IEC 27036 controls to audits and evidenceBuild contract clauses, SBOM requirements, and playbooks for third- and fourth-party breachesIncludes assessment templates, evidence checklists, and incident playbooks you can adaptBook DescriptionReduce supply chain cyber risk by turning third-party risk management into an operational program that connects procurement, legal, and security decisions. This book replaces checkbox assessments with a lifecycle approach you can apply from onboarding through offboarding, so vendor risk tiering, control mapping, and continuous monitoring drive clear outcomes.You learn how to align supplier oversight with major obligations and guidance, including DORA, GDPR, Executive Order 14028, NIST C-SCRM, and ISO/IEC 27036. You also get practical methods for strengthening contracts and SLAscovering audit rights, breach notification, liability, and security requirements that flow down to critical subcontractors.From threat intelligence and security ratings to incident response playbooks for vendor and sub-vendor breaches, the book shows how to handle real signals, not just survey answers. Written by practitioners with deep experience in supply chain risk and offensive security, it also explains how SBOM standards and AI-assisted scoring can support scalable governance. By the end, you can build and mature an intelligence-driven TPRM program focused on measurable resilience.What you will learnLearn how vendor ecosystems become attack pathsCategorize third- and fourth-party supply chain risksCreate risk tiers and segmentation based on business impactDesign a lifecycle workflow from onboarding to offboardingSelect controls using NIST and ISO supply chain guidanceTranslate DORA, GDPR, and EO 14028 duties into controlsPrepare evidence packs for audits and regulator questionsPlan continuous monitoring beyond annual questionnairesWho this book is forThis book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. Compliance teams and in-house counsel working with DORA, GDPR, HIPAA, and related requirements will also benefit. Basic familiarity with security principles and vendor management helps. Connect third-party risk management and supply chain cybersecurity. Build a lifecycle for vendor risk assessment, align with NIST C-SCRM, ISO 27036, DORA, and implement SBOM, monitoring, and vendor breach response. This item is printed on demand. Shipping may be from our Sydney, NSW warehouse or from our UK or US warehouse, depending on stock availability. N° de réf. du vendeur 9781806708116
Quantité disponible : 1 disponible(s)
Vendeur : AHA-BUCH GmbH, Einbeck, Allemagne
Taschenbuch. Etat : Neu. nach der Bestellung gedruckt Neuware - Printed after ordering - Align TPRM and cybersecurity, classify supply chain risks, build a lifecycle program, and map NIST C-SCRM, ISO/IEC 27036, DORA, GDPR, and EO 14028 to evidence and audits.Key Features:- Align procurement, legal, and security priorities around shared risk outcomes- Apply a clear taxonomy for cyber, operational, regulatory, and reputational risk- Use a lifecycle blueprint to structure assessment and ongoing oversight- Map NIST C-SCRM, ISO/IEC 27036, DORA, and EO 14028 to audit evidenceBook Description:Modern organizations rely on complex vendor ecosystems, but third-party risk management (TPRM) and cybersecurity often operate in silos. This book shows how to connect vendor risk management with supply chain cybersecurity using a practical, lifecycle-driven approach.You'll design a program covering onboarding, vendor risk assessment, continuous monitoring, and offboarding. You'll begin by examining why TPRM and cybersecurity often operate in separate lanes, and what that gap costs in downtime, breach impact, and compliance exposure. Next, you'll develop a modern taxonomy of supply chain risk, including fourth-party dependencies and software supply chain concerns, so risk discussions use consistent categories and measurable assumptions.From there, you'll adopt a lifecycle-based model to structure vendor onboarding, assessment, monitoring, and offboarding-supported by vendor tiering, segmentation, and control mapping. The final chapter focuses on the regulatory blueprint: how to interpret NIST C-SCRM, ISO/IEC 27036, DORA, GDPR, and Executive Order 14028, then convert them into evidence-driven controls and audit-ready documentation.What You Will Learn:- Learn how vendor ecosystems become attack paths- Categorize third- and fourth-party supply chain risks- Create risk tiers and segmentation based on business impact- Design a lifecycle workflow from onboarding to offboarding- Select controls using NIST and ISO supply chain guidance- Translate DORA, GDPR, and EO 14028 duties into controls- Prepare evidence packs for audits and regulator questions- Plan continuous monitoring beyond annual questionnairesWho this book is for:This book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. It also helps compliance stakeholders who need a shared, workable method to manage supplier cyber exposure. Basic familiarity with security principles and vendor management helps.Table of Contents- The Disconnect - TPRM vs. Cybersecurity in the Supply Chain- The New Attack Surface - A Taxonomy of Supply Chain Risks- The Foundational Framework - A TPRM-Driven Security Lifecycle- The Regulatory Blueprint - Navigating Key Frameworks. N° de réf. du vendeur 9781806708116
Quantité disponible : 2 disponible(s)
Vendeur : preigu, Osnabrück, Allemagne
Taschenbuch. Etat : Neu. TPRM-Driven Supply Chain Cybersecurity | Connecting TPRM and supply chain security for operational resilience | Eric Richardson (u. a.) | Taschenbuch | Englisch | 2026 | Packt Publishing | EAN 9781806708116 | Verantwortliche Person für die EU: Libri GmbH, Europaallee 1, 36244 Bad Hersfeld, gpsr[at]libri[dot]de | Anbieter: preigu Print on Demand. N° de réf. du vendeur 135558823
Quantité disponible : 5 disponible(s)