Safeguard Documentation Center
Third Party Risk Manager

Risk Assessment

Analyze and score vendor risk based on SBOM analysis

Risk Assessment

Automatically assess vendor risk based on SBOM analysis, vulnerability data, and compliance status.

Risk Score

Each vendor receives a risk score (0-100):

ScoreRisk LevelDescription
0-25CriticalImmediate action required
26-50HighSignificant concerns
51-75MediumModerate risk
76-100LowAcceptable risk

Risk Factors

Vulnerability Risk

Based on SBOM analysis:

  • Critical vulnerability count
  • High vulnerability count
  • EPSS scores (exploit probability)
  • Known exploited vulnerabilities

Compliance Risk

Based on SBOM quality:

  • EO 14028 compliance percentage
  • Missing required fields
  • Outdated SBOM (age)
  • Format validity

Component Risk

Based on dependency health:

  • Abandoned packages
  • License compliance
  • Transitive dependency depth
  • Known malicious packages

Operational Risk

Based on vendor factors:

  • Response time to requests
  • Update frequency
  • Security incident history
  • Contract compliance

Assessment Report

Generate detailed risk reports:

  1. Select vendor(s)
  2. Click Generate Report
  3. Report includes:
    • Executive summary
    • Risk score breakdown
    • Vulnerability details
    • Compliance gaps
    • Recommendations

Comparative Analysis

Compare vendors side-by-side:

  • Risk scores
  • Vulnerability counts
  • Compliance status
  • Trend over time

Risk Acceptance

Document accepted risks:

  1. Review the risk finding
  2. Click Accept Risk
  3. Provide business justification
  4. Set review date
  5. Obtain required approvals

Remediation Tracking

Track vendor remediation efforts:

  • Requested fixes
  • Vendor commitments
  • Progress updates
  • Verification status

On this page