Vendor Security Guide
Track your third-party vendors, their criticality, and review status.
Adding a vendor
From the Vendor Security page, record the vendor's name, a criticality tier, and manual review notes. Criticality is your own judgment call (how much would it hurt if this vendor had a security incident?), not something calculated automatically.
Review status
Set a security-review status and a next-review date. A vendor whose next-review date has passed shows an Overdue badge, so you can see at a glance which relationships need a fresh look.
Linking a vendor to a risk
A vendor can link to a single Risk Register entry, useful when a vendor relationship itself is the thing you're tracking as an external risk. See the GRC guide for how the Risk Register's treatment plans work.
Who can do what
Owners, admins, and security managers can add and manage vendors. Any member can view the inventory.