TPRM-Driven Supply Chain Cybersecurity | Connecting TPRM and supply chain security for operational resilience
Lingua: inglese
Editore: Packt Publishing, 2026
- Brossura
- Nuovo

Condizione: Nuovo
EUR 58,05
Quantità: 5 disponibili
Aggiungi al carrelloDescrizione dell’articolo da parte del venditore
TPRM-Driven Supply Chain Cybersecurity | Connecting TPRM and supply chain security for operational resilience | Eric Richardson (u. a.) | Taschenbuch | Englisch | 2026 | Packt Publishing | EAN 9781806708116 | Verantwortliche Person für die EU: Libri GmbH, Europaallee 1, 36244 Bad Hersfeld, gpsr[at]libri[dot]de | Anbieter: preigu Print on Demand.
Codice articolo 135558823
- Titolo
- TPRM-Driven Supply Chain Cybersecurity | Connecting TPRM and supply chain security for operational resilience
- Autore
- Eric Richardson (u. a.)
- Editore
- Packt Publishing
- Anno di pubblicazione
- 2026
- Condizione
- Neu
- Rilegatura
- Taschenbuch
- Lingua
- inglese
- ISBN 10
- 1806708116
- ISBN 13
- 9781806708116
- Peso dell'articolo
- 640 grammi
- Dimensioni
- 235 x 191 x 19 mm
- Cataloghi dei venditori
- Bücher
Integrate cybersecurity into TPRM to reduce vendor breach impact, meet DORA and NIST C-SCRM expectations, and monitor fourth-party exposure using SBOM-driven diligence, threat intelligence, and automation.
Key Features
- Design a lifecycle-based TPRM program that ties vendor decisions to cyber risk
- Map DORA, NIST C-SCRM, and ISO/IEC 27036 controls to audits and evidence
- Build contract clauses, SBOM requirements, and playbooks for third- and fourth-party breaches
- Includes assessment templates, evidence checklists, and incident playbooks you can adapt
Book Description
Reduce supply chain cyber risk by turning third-party risk management into an operational program that connects procurement, legal, and security decisions. This book replaces checkbox assessments with a lifecycle approach you can apply from onboarding through offboarding, so vendor risk tiering, control mapping, and continuous monitoring drive clear outcomes.
You learn how to align supplier oversight with major obligations and guidance, including DORA, GDPR, Executive Order 14028, NIST C-SCRM, and ISO/IEC 27036. You also get practical methods for strengthening contracts and SLAs—covering audit rights, breach notification, liability, and security requirements that flow down to critical subcontractors.
From threat intelligence and security ratings to incident response playbooks for vendor and sub-vendor breaches, the book shows how to handle real signals, not just survey answers. Written by practitioners with deep experience in supply chain risk and offensive security, it also explains how SBOM standards and AI-assisted scoring can support scalable governance. By the end, you can build and mature an intelligence-driven TPRM program focused on measurable resilience.
What you will learn
- Learn how vendor ecosystems become attack paths
- Categorize third- and fourth-party supply chain risks
- Create risk tiers and segmentation based on business impact
- Design a lifecycle workflow from onboarding to offboarding
- Select controls using NIST and ISO supply chain guidance
- Translate DORA, GDPR, and EO 14028 duties into controls
- Prepare evidence packs for audits and regulator questions
- Plan continuous monitoring beyond annual questionnaires
Who this book is for
This book is for cybersecurity leaders, TPRM/VRM practitioners, risk managers, and procurement professionals who need a repeatable way to evaluate and monitor vendors and critical suppliers. Compliance teams and in-house counsel working with DORA, GDPR, HIPAA, and related requirements will also benefit. Basic familiarity with security principles and vendor management helps.
Table of Contents
- The Disconnect — TPRM vs. Cybersecurity in the Supply Chain
- The New Attack Surface — A Taxonomy of Supply Chain Risks
- The Foundational Framework — A TPRM-Driven Security Lifecycle
- The Regulatory Blueprint — Navigating Key Frameworks
- The Legal Foundation of Embedding Cybersecurity into Contracts
- The Unseen Threat – Managing Fourth-Party Risk
- Deep Dive – Threat Intelligence: Uncovering Hidden Supply Chain Risks
- The Incident Blueprint - Responding to Third- and Fourth-Party Breaches
- Measuring and Advancing TPRM Maturity
- Connecting TPRM and SCM – Due Diligence of Suppliers and Understanding Threats
- Understanding Your Service Provider's Software Bill of Material
- The Technological Imperative – Leveraging AI and Automation
- The Software Ingredient List – SBOM and Supply Chain Security
- Building an Advanced Program - From Compliance to Resilience
"Riassunto" può appartenere a un’altra edizione di questo titolo.
Informazioni sull’autore
Eric Richardson has had a distinguished technology career in roles from CISO/ to executive to volunteer AP Comp Sci teacher with over 30 years of experience specializing in the critical intersection of Cybersecurity, Artificial Intelligence, and Operational Risk. Currently serving as the Global Leader of Artificial Intelligence and Security Engineering at Cisco, he spearheads corporate-wide standards for secure AI implementation and evaluates complex architectures to ensure robust security controls. His deep technical expertise in AI is evidenced by his authorship of "Prompt Engineering: Hands-on guide to prompt engineering for AI interactions". Eric resides in Washington State with his Wife Stacie and his daughters Katie and Maddie. Eric possesses a Masters in Computer Science with a focus on cybersecurity Engineering as well as a MBA.
Filipi Pires is an internationally recognized cybersecurity leader, researcher, and global speaker specializing in adversary emulation, identity security, and offensive security operations. With over 15 years of experience in the cybersecurity industry, he has built a career at the intersection of technical research, product strategy, and community leadership, helping organizations understand, simulate, and defend against real-world cyber threats. He currently serves as Head of Technical Advocacy at SCYTHE, where he leads global initiatives focused on Breach & Attack Simulation (BAS) and Adversarial Emulation & Validation (AEV). In this role, Filipi works closely with enterprises, government organizations, and security teams worldwide to operationalize adversary simulation, validate defensive controls, and mature cyber resilience programs through realistic attack scenarios. Beyond his corporate role, Filipi is the Founder & Investor at CROSS-INTEL, a global cybersecurity consulting and market-expansion firm, and Advisor & Investor at Sherlockeye, an AI-driven OSINT intelligence platform designed to accelerate cyber investigations and threat intelligence operations. He serves as Organizer of BSides Porto, one of Europe's fastest-growing community cybersecurity conferences, and Director of the Red Team Village at DEF CON, one of the most respected offensive security communities in the world. He is also Senior Advisor at Raíces Cyber Academy and Founder of the Red Team Community across Brazil and Latin America, initiatives dedicated to developing the next generation of offensive security professionals. As an international conference speaker, Filipi has delivered technical presentations and research at many of the world's most prestigious cybersecurity events, including multiple editions of Black Hat USA, DEF CON, Black Hat Middle East & Africa, RSA Conference-related events, and numerous BSides conferences worldwide. His talks focus on identity-centric attack paths, cloud privilege escalation, supply-chain compromise, breach simulation, and real adversary tradecraft. He has been recognized among the Top 3% Most Active Security Speakers globally, reflecting both the volume and impact of his contributions to the industry. His industry recognitions include AWS Community Builder and Snyk Ambassador. He is also known globally as an advocate for hacking through his long-standing initiative “Hacking is NOT a Crime,” promoting responsible research, education, and collaboration across the cybersecurity ecosystem. Through his work spanning industry, research, education, and community leadership, Filipi Pires continues to advance adversary simulation practices, identity-focused security, and the global maturation of offensive cybersecurity capabilities.
"Descrizione articolo" può appartenere a un’altra edizione di questo titolo.
preigu
Osnabrück, Germania
Venditore AbeBooks dal 5 agosto 2024
Tariffe di spedizione da Germania a U.S.A.
| Articolo | Da 60 a 60 giorni lavorativi | Da 60 a 60 giorni lavorativi |
|---|---|---|
| Primo articolo | EUR 70,00 | EUR 70,00 |
Metodi di pagamento
- PayPal
Descrizione dello Store
preigu betreibt einen Onlineversandhandel mit über 1 Mio. Produkten in verschiedenen Sortimenten. Das Kernsortiment besteht aus Büchern, Medien und Spielwaren. Ein gelungenes Einkaufserlebnis ist das Ziel einer jeden Bestellung bei preigu, denn der Kunde und seine Zufriedenheit stehen an erster Stelle. preigu setzt daher auf einen kompetenten Kundenservice, funktionierende Prozesse und schnelle Reaktion.
Specializzazione
Bücher, SpielwarenInformazioni sull’azienda del venditore
preigu GmbH & Co. KG
Lengericher Landstraße 19
Osnabrück, Germania 49078
Condizioni di vendita
About Us
Legal website operator identification:
preigu GmbH & Co. KG
Lengericher Landstr. 19
49078 Osnabrück
Germany
Telephone: +49 (0) 541 / 580 72 84
Email: mail@preigu.de
VAT No: DE 455 380 498
AG Osnabrück - HRA 209647
PhG: preigu Verwaltung GmbH
AG Osnabrück - HRB 221793
CEO: Ansas Meyer
We are neither willing nor obliged to participate in dispute resolution proceedings before consumer arbitration boards.
We are a member of the initiative "FairCommerce" since 30.11.2016.
For more information, see: https://www.haendlerbund.de/de/haendlerbund/interessenvertretung/faircommerce
Diritto di recesso
Instructions for revocation
Right of withdrawal for the sale of goods
Revocation right for consumers
(A ‘consumer' is any natural person who concludes a legal transaction which, to an overwhelming extent, cannot be attributed to either his commercial or independent professional activities.)
Instructions for revocation
Revocation right
You have the right to revoke this contract within 14 days without specifying any reasons.
The revocation period is 14 days with effect from the day,
-
on which you or a third party nominated by you, which is not the carrier, had taken possession of the products, provided you had ordered one or more products within the scope of a standard order and this/these product/products is/are delivered uniformly;
-
on which you or a third party nominated by you, which is not the carrier, had taken possession of the last product, provided you had ordered several products within the scope of a standard order and these products are delivered separately;
-
on which you or a third party nominated by you, which is not the carrier, had taken possession of the last part delivery or the last unit, provided you had ordered a product, which is delivered in several part deliveries or units;
To exercise your right of withdrawal, you must inform us (preigu GmbH & Co. KG, Lengericher Landstr. 19, 49078 Osnabrück, Telephone number: +49 (0) 541 / 580 72 84, E-Mail address: mail@preigu.de) by means of a clear declaration (e.g. a letter sent by post, or an e-mail) of your decision to withdraw from this contract. You can use the attached model withdrawal form for this purpose, which is, however, not mandatory.
You can also exercise your right of withdrawal online by clicking on a button labelled accordingly (such as ‘Withdraw from contract' or similar) on the AbeBooks/ZVAB website. If you use this online function, you will immediately receive a confirmation of receipt on a durable medium (e.g. via email) containing information on the content of the withdrawal notice, as well as the date and time of its receipt.
In order to safeguard the revocation period, it is sufficient that you send the notification about the exercise of the revocation right before the expiry of the revocation period.
Consequences of the revocation
If you revoke this contract, we shall repay all the payments, which we received from you, including the delivery costs (with the exception of additional costs, which arise from that fact that you selected a form of delivery other than the most reasonable standard delivery offered by us), immediately and at the latest within 14 days from the day on which we received the notification about the revocation of this contract from you. We use the same means of payment, which you had originally used during the original transaction, for this repayment unless expressly agreed otherwise with you; you will not be charged any fees owing to this repayment.
We can refuse the repayment until the products are returned to us or until you have furnished evidence that you have sent the products back to us, depending on whichever is earlier.
You must return or transfer the products to us immediately and, in any case, at the latest within 14 days with effect from the day on which you inform us of the revocation of this contract. The deadline is maintained if you send the products before the expiry of the 14 day deadline.
You bear the direct costs for returning the products.
You must pay for any depreciation of the products only if this depreciation can be attributed to any handling with you that was not necessary for checking the condition, features and functionality of the products.
Criteria for exclusion or expiry
The revocation right is not available for contracts
-
for delivery of products, which are not prefabricated and for whose manufacturing an individual selection or stipulation by the consumer is important or which are clearly tailored to the personal requirements of the consumer;
-
for delivery of products, which can spoil quickly or whose use-by date would be exceeded quickly;
-
for delivery of alcoholic drinks, whose price was agreed at the time of concluding the contract, which however can be delivered 30 days after the conclusion of the contract at the earliest and whose current value depends on the fluctuations in the market, on which the entrepreneur has no influence;
-
for delivery of newspapers, periodicals or magazines with the exception of subscription contracts. The revocation right expires prematurely in case of contracts
-
for delivery of sealed products, which are not suitable for return for reasons of health protection or hygiene if their seal has been removed after the delivery;
-
for delivery of products if they have been mixed inseparably with other goods after the delivery, owing to their condition;
-
for delivery of sound or video recording or computer software in a sealed package if the seal has been removed after the delivery.
Specimen - revocation form
(If you wish to revoke the contract, please fill up this form and send it back to us.)
-
To preigu GmbH & Co. KG, Lengericher Landstr. 19, 49078 Osnabrück, Email address: mail@preigu.de :
-
I/we () herewith revoke the contract concluded by me/ us () regarding the purchase of the following products ()/
the provision of the following service () -
Ordered on ()/ received on ()
-
Name of the consumer(s)
-
Address of the consumer(s)
-
Signature of the consumer(s) (only in case of a notification on paper)
-
Date
(*) Cross out the incorrect option.