TPR-215Third-Party & Supply Chain Risk
Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations
What you leave with
A CUEC register: every complementary control from your critical vendors, mapped to an internal control, an owner and evidence.
Same obligation, two realities
Early-stage and SMEthree vendors, fifteen CUECs, mostly about access.
Enterprisehundreds of CUECs feeding the control library and the risk register.
How the course runs
- The obligation: where the responsibility comes from, cited by section.
- Two realities: how it is met in a small organisation and in an enterprise.
- The method: step-by-step practice with templates and edge cases.
- Paired labs: complete the one matching your work, read the other.
- Artefact and assessment: submit the artefact; a rubric and a short scenario quiz decide the certificate.