Third-Party Risk Management SOP
How to manage cybersecurity risks associated with third-party components.
Written By Micah
This Standard Operating Procedure (SOP) outlines comprehensive processes for managing cybersecurity risks associated with third-party components and services used in medical devices. It covers key aspects including risk assessment, contract management, ongoing monitoring, Software Bill of Materials (SBOM) management, vulnerability management, and incident response specific to third-party components. The SOP emphasizes the importance of continuous assessment, clear communication with third-party providers, and maintaining detailed documentation to effectively manage and mitigate risks associated with third-party components and services in medical devices.
How to use these templates:
Click on the links to access the templates
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload