← Security+ glossary

Compliance and third-party risk

Third-party / vendor risk

Third-party risk is the danger that arises from relying on external vendors, because their weak security can endanger your data and systems (e.g. an attack on a vendor opens a path to you). Outsourcing the processing transfers the task but not the entire responsibility, because the controller still answers to the data subjects and the regulator, which is why oversight of the vendor is continuous, not one-off.

All Security+ guides →

Related terms

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations