What is the first step in establishing a third-party risk management (TPRM) program?
-
A
Send security questionnaires to all vendors immediately
-
B
Create an inventory and risk tiering of all third-party relationships
-
C
Require all vendors to obtain ISO 27001 certification
-
D
Conduct penetration tests on vendor systems