I just released a report for Dark Reading on how to build a multi-enterprise vulnerability management program. If you are dealing with outsourced vendors, or an outsourced supply chain, you should definitely give the article a read.
To summarize the article:
I offer many more details and tips within the article but step #1 is so critical that an entire article should be dedicated to just that!
Tagged Business process, enterprise vulnerability, legal contracts, management program, security, security processes, supply chain, Supply chain management, vulnerability, vulnerability management