TOP
💡 邁向小一的第一步!給孩子一本「查得到自信」的專屬辭典,輕鬆跨越閱讀關卡!🚀
TPRM-Driven Supply Chain Cybersecurity: Connecting TPRM and supply chain security for operational resilience

TPRM-Driven Supply Chain Cybersecurity: Connecting TPRM and supply chain security for operational resilience

商品資訊

定價
:NT$ 2250 元
無庫存,下單後進貨(到貨天數約30-45天)
下單可得紅利積點 :67 點
商品簡介

商品簡介

Align TPRM and cybersecurity, classify supply chain risks, build a lifecycle program, and map NIST C-SCRM, ISO/IEC 27036, DORA, GDPR, and EO 14028 to evidence and audits.

Key Features:

- Align procurement, legal, and security priorities around shared risk outcomes

- Apply a clear taxonomy for cyber, operational, regulatory, and reputational risk

- Use a lifecycle blueprint to structure assessment and ongoing oversight

- Map NIST C-SCRM, ISO/IEC 27036, DORA, and EO 14028 to audit evidence

Book Description:

Modern organizations rely on complex vendor ecosystems, but third-party risk management (TPRM) and cybersecurity often operate in silos. This book shows how to connect vendor risk management with supply chain cybersecurity using a practical, lifecycle-driven approach.

You'll design a program covering onboarding, vendor risk assessment, continuous monitoring, and offboarding. You'll begin by examining why TPRM and cybersecurity often operate in separate lanes, and what that gap costs in downtime, breach impact, and compliance exposure. Next, you'll develop a modern taxonomy of supply chain risk, including fourth-party dependencies and software supply chain concerns, so risk discussions use consistent categories and measurable assumptions.

From there, you'll adopt a lifecycle-based model to structure vendor onboarding, assessment, monitoring, and offboarding-supported by vendor tiering, segmentation, and control mapping. The final chapter focuses on the regulatory blueprint: how to interpret NIST C-SCRM, ISO/IEC 27036, DORA, GDPR, and Executive Order 14028, then convert them into evidence-driven controls and audit-ready documentation.

What You Will Learn:

- Learn how vendor ecosystems become attack paths

- Categorize third- and fourth-party supply chain risks

- Create risk tiers and segmentation based on business impact

- Design a lifecycle workflow from onboarding to offboarding

- Select controls using NIST and ISO supply chain guidance

- Translate DORA, GDPR, and EO 14028 duties into controls

- Prepare evidence packs for audits and regulator questions

- Plan continuous monitoring beyond annual questionnaires

Who this book is for:

This book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. It also helps compliance stakeholders who need a shared, workable method to manage supplier cyber exposure. Basic familiarity with security principles and vendor management helps.

Table of Contents

- The Disconnect - TPRM vs. Cybersecurity in the Supply Chain

- The New Attack Surface - A Taxonomy of Supply Chain Risks

- The Foundational Framework - A TPRM-Driven Security Lifecycle

- The Regulatory Blueprint - Navigating Key Frameworks

購物須知

外文書商品之書封,為出版社提供之樣本。實際出貨商品,以出版社所提供之現有版本為主。部份書籍,因出版社供應狀況特殊,匯率將依實際狀況做調整。

無庫存之商品,在您完成訂單程序之後,將以空運的方式為你下單調貨。為了縮短等待的時間,建議您將外文書與其他商品分開下單,以獲得最快的取貨速度,平均調貨時間為1~2個月。

為了保護您的權益,「三民網路書店」提供會員七日商品鑑賞期(收到商品為起始日)。

若要辦理退貨,請在商品鑑賞期內寄回,且商品必須是全新狀態與完整包裝(商品、附件、發票、隨貨贈品等)否則恕不接受退貨。

定價:100 2250
無庫存,下單後進貨
(到貨天數約30-45天)

暢銷榜

客服中心

收藏

會員專區