Overview
Third-party risk management is the discipline of evaluating the security and compliance posture of the vendors, suppliers and service providers your organisation depends on. CyberGuard treats third parties as a first-class concern with their own object graph, separate from internal compliance work — because permissions, lifecycle and reporting all differ.
Where to find it
Section titled “Where to find it”Third parties → Overview in the sidebar. The whole section is gated by permission on entities, solutions and entity assessments, so a user who can see none of those sees no dashboard.
The model
Section titled “The model”Five objects carry the third-party landscape:
| Object | What it is |
|---|---|
| Entity | A vendor, supplier, partner or subsidiary. The unit of organisational identity. |
| Solution | A specific product or service an entity provides. One entity, many solutions. |
| Contract | The formal agreement covering one or more solutions, with dates, expense and notice periods. |
| Representative | The person on the entity’s side who answers questionnaires and signs off. |
| Entity assessment | The actual review of a third party, usually a questionnaire the vendor fills in. |
They compose in the obvious direction: an entity provides solutions, a contract covers some of them, a representative speaks for the entity, and an entity assessment reviews the relationship. Your own organisation is modelled as an entity too, which is what lets a contract name both a provider and a beneficiary.
Why a separate model
Section titled “Why a separate model”Treating third parties as a parallel surface, rather than as “another perimeter”, matters for three reasons:
- Permissions differ. A vendor’s representative needs to answer one questionnaire and see nothing else — not a role in your domain.
- Lifecycle differs. Contracts renew, vendors come and go, solutions get replaced. Your internal frameworks stay stable across all of it.
- Reporting differs. Third-party reporting aggregates across many entities rather than drilling down inside one.
The dashboard
Section titled “The dashboard”The Overview page is a wall of cards, one per entity assessment, grouped under the domain that owns it. Each domain header links through to the domain itself and carries a count of the assessments underneath.
The front of a card shows:
- The provider — the entity’s name, linking to the assessment.
- The conclusion as a coloured badge: Blocker in red, Warning in amber, Ok in green, and ongoing in blue while no conclusion has been reached.
- The solutions covered.
- The baseline — the framework backing the questionnaire.
- Compliance review progress, as a bar that runs red below 50%, amber below 75% and green above.
Flip the card with the control in its corner for the operational side: last update, due date, questions completion, the reviewers, and the assessment’s observation.
A typical cycle
Section titled “A typical cycle”- Register the entity, and the solutions it provides to you.
- Add a representative and, if they will answer online, create their user at the same time.
- Create an entity assessment, tick Create audit, and pick the framework or questionnaire to send.
- Assign the representatives on the questionnaire and use Send questionnaire to invite them.
- Watch the card here as the answers land, then review, set the conclusion, and record the residual risk you accept.
Respondents answer through the auditee experience rather than in your workspace — see Auditee mode and portals.
Related
Section titled “Related”- Entity assessments — running the review itself.
- Entities — the register of third parties.
- Analytics — the wider dashboards.
