๐ช๐ต๐ฎ๐
InfosecTrain, a leading cybersecurity training provider, is hosting a 2-Day TPRM: Third-Party Risk Management Fast-Track Bootcamp. This bootcamp is a two-day program that will explain how organizations manage risks from third-party relationships. It will cover TPRM fundamentals, its scope across the vendor lifecycle, and how it works alongside procurement and vendor management with clear ownership and accountability. Key risk concepts, including risk appetite, inherent versus residual risk, and their impact on vendor selection, due diligence, and monitoring, will be explored. The bootcamp will also discuss alignment with frameworks like ISO/IEC 27001:2022 and SOC 2. Day two will focus on program execution, governance, third-party categorization, challenges, and professional growth opportunities within TPRM and GRC roles.
๐ช๐ต๐ฒ๐ป
28 - 29 March 2026
7:00 PM โ 11:00 PM
๐ฆ๐ฝ๐ฒ๐ฎ๐ธ๐ฒ๐ฟ
Kavitha
17+ Years of Experience
Information Security | IT Governance | Compliance Audit | ISO 27001 | IT Service Management
๐ช๐ต๐ ๐๐๐๐ฒ๐ป๐ฑ
Attending this bootcamp will equip professionals with practical skills to navigate the complexities of third-party risk in real-world organizational settings. It will help develop sound judgment in assessing risk, setting thresholds, and ensuring accountability across functions. Participants will gain insights into aligning TPRM with organizational strategies, regulatory expectations, and governance requirements. The program will also support cross-functional collaboration with teams like InfoSec, Legal, and Procurement, strengthening professional influence and decision-making. Additionally, it will provide guidance on career growth in TPRM and broader governance, risk, and compliance roles, making it valuable for those looking to formalize their expertise and advance in risk management and third-party oversight.
Agenda (Two Days of Transformative Learning)
๐ซ๐๐ 1: ๐ป๐ท๐น๐ด ๐ญ๐๐๐๐
๐๐๐๐๐๐, ๐น๐๐๐ ๐ช๐๐๐๐๐๐๐ & ๐ญ๐๐๐๐๐๐๐๐ ๐จ๐๐๐๐๐๐๐๐
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ญ: ๐๐ป๐๐ฟ๐ผ๐ฑ๐๐ฐ๐๐ถ๐ผ๐ป ๐๐ผ ๐ง๐ต๐ถ๐ฟ๐ฑ-๐ฃ๐ฎ๐ฟ๐๐ ๐ฅ๐ถ๐๐ธ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐บ๐ฒ๐ป๐
What is Third-Party Risk Management (TPRM)?
Scope of TPRM across the vendor lifecycle
Why TPRM is critical in todayโs risk and regulatory landscape
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ฎ: ๐ฃ๐ฟ๐ผ๐ฐ๐๐ฟ๐ฒ๐บ๐ฒ๐ป๐, ๐ฉ๐ฒ๐ป๐ฑ๐ผ๐ฟ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐บ๐ฒ๐ป๐ & ๐ง๐ฃ๐ฅ๐ โ ๐๐น๐ฒ๐ฎ๐ฟ ๐๐ผ๐๐ป๐ฑ๐ฎ๐ฟ๐ถ๐ฒ๐
Procurement vs Vendor Management vs TPRM
How these functions work together
Clear ownership, responsibilities, and outcomes
Avoiding role overlap and governance gaps
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ฏ: ๐ช๐ต๐ ๐ง๐ฃ๐ฅ๐ ๐ ๐ฎ๐๐๐ฒ๐ฟ๐ ๐ง๐ผ๐ฑ๐ฎ๐ & ๐ข๐ฟ๐ด๐ฎ๐ป๐ถ๐๐ฎ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ข๐๐ป๐ฒ๐ฟ๐๐ต๐ถ๐ฝ
Growing third-party ecosystems and outsourcing risks
Regulatory and customer expectations
Shared ownership model for effective TPRM
Enabling business without slowing it down
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ฐ: ๐ฅ๐ถ๐๐ธ ๐๐๐ป๐ฑ๐ฎ๐บ๐ฒ๐ป๐๐ฎ๐น๐ ๐ณ๐ผ๐ฟ ๐ง๐ฃ๐ฅ๐
What is risk and how it impacts organizations
Risk appetite and organizational tolerance
Inherent risk vs residual risk
Importance of residual risk in TPRM decision-making
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ฑ: ๐ฅ๐ถ๐๐ธ ๐๐ฝ๐ฝ๐ฒ๐๐ถ๐๐ฒ & ๐๐๐ ๐๐บ๐ฝ๐ฎ๐ฐ๐ ๐ผ๐ป ๐ง๐ฃ๐ฅ๐ ๐๐ฒ๐ฐ๐ถ๐๐ถ๐ผ๐ป๐
Risk-based vendor selection and onboarding
Depth of due diligence and monitoring
Risk escalation thresholds and reporting
Contractual and control implications
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ฒ: ๐ง๐ฃ๐ฅ๐ ๐๐น๐ถ๐ด๐ป๐บ๐ฒ๐ป๐ ๐๐ถ๐๐ต ๐๐ป๐ฑ๐๐๐๐ฟ๐ ๐๐ฟ๐ฎ๐บ๐ฒ๐๐ผ๐ฟ๐ธ๐
Aligning TPRM with ISO/IEC 27001:2022
SOC 2 Trust Services Criteria and vendor risk
Governance, accountability, and evidence-based oversight
Positioning TPRM as a governance enabler
๐ซ๐๐ 2: ๐ป๐ท๐น๐ด ๐บ๐๐๐๐๐๐๐๐, ๐ฌ๐๐๐๐๐๐๐๐ & ๐ท๐๐๐๐๐๐๐๐๐๐๐ ๐ฎ๐๐๐๐๐
Module 7: TPRM Fundamentals & Scope
Core fundamentals of a TPRM program
Scope of third parties (technology & non-technology)
Inclusion of vendors, partners, consultants, and contractors
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ด: ๐ง๐ฃ๐ฅ๐ ๐ฅ๐ผ๐น๐ฒ๐, ๐ฅ๐ฒ๐๐ฝ๐ผ๐ป๐๐ถ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ & ๐๐ผ๐๐ฒ๐ฟ๐ป๐ฎ๐ป๐ฐ๐ฒ
Roles of TPRM teams, leadership, and business units
Collaboration with InfoSec, Legal, Procurement, Audit
Shared accountability across the organization
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ต: ๐ง๐ต๐ถ๐ฟ๐ฑ-๐ฃ๐ฎ๐ฟ๐๐ ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป & ๐ฉ๐ฒ๐ป๐ฑ๐ผ๐ฟ ๐๐น๐ฎ๐๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป
Identifying and classifying third parties
Risk levels, criticality, and strategic importance
Why categorization is foundational to effective TPRM
Risk-based prioritization and resource allocation
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ญ๐ฌ: ๐๐๐ฟ๐ฟ๐ฒ๐ป๐ ๐๐ต๐ฎ๐น๐น๐ฒ๐ป๐ด๐ฒ๐ ๐ถ๐ป ๐ง๐ฃ๐ฅ๐ ๐ฃ๐ฟ๐ผ๐ด๐ฟ๐ฎ๐บ๐
Governance and standardization gaps
Manual and inefficient assessments
Limited visibility and weak ongoing monitoring
Regulatory pressure and vendor fatigue
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ญ๐ญ: ๐ฅ๐ผ๐ฎ๐ฑ๐บ๐ฎ๐ฝ ๐๐ผ ๐๐ฒ๐ฐ๐ผ๐บ๐ถ๐ป๐ด ๐ฎ ๐ง๐ฃ๐ฅ๐ ๐ฃ๐ฟ๐ผ๐ณ๐ฒ๐๐๐ถ๐ผ๐ป๐ฎ๐น
Skills, knowledge areas, and career progression
Understanding how to grow in TPRM roles
Positioning yourself in governance, risk, and compliance domains
๐ ๐ผ๐ฑ๐๐น๐ฒ ๐ญ๐ฎ: ๐๐ป๐ผ๐๐น๐ฒ๐ฑ๐ด๐ฒ ๐๐ต๐ฒ๐ฐ๐ธ & ๐ช๐ฟ๐ฎ๐ฝ-๐จ๐ฝ
Quiz and interactive discussion
Key takeaways from the bootcamp
Closing notes and next steps
๐๐ฒ๐ ๐ง๐ฎ๐ธ๐ฒ๐ฎ๐๐ฎ๐๐
Practical understanding of TPRM foundations and vendor risk management
Hands-on exposure to frameworks and risk-based decision-making
Interactive activities, quizzes, and real-world scenarios
Clarity on TPRM roles and career growth in risk and compliance
Apply TPRM concepts to real-world vendor scenarios
Earn 8 CPE Credits
๐ฅ๐ฒ๐ด๐ถ๐๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป ๐๐ถ๐ป๐ธ:
https://www.infosectrain.com/bootcamp/third-party-risk-management-fast-track-bootcamp/
๐๐ฏ๐ผ๐๐ ๐๐ป๐ณ๐ผ๐๐ฒ๐ฐ๐ง๐ฟ๐ฎ๐ถ๐ป
InfosecTrain is a recognized leader in cybersecurity training, focused on enhancing awareness and expertise in data protection, cybersecurity, and compliance. Through expert-led sessions and informative events, InfosecTrain equips professionals and organizations to protect sensitive information and effectively navigate the constantly evolving cybersecurity landscape. To know more about training programs offered by InfosecTrain:
Please write back to
[email protected] or call at IND: 1800-843-7890 (Toll-Free) / US: +1 657-221-1127 / UAE: +971 569-908-131