Supply chain risk was already a well-established category in IT risk management frameworks before SolarWinds and before Log4Shell. ISACA’s CRISC content has included third-party and supply chain risk considerations for years. What has changed in the past eighteen months is not the existence of the risk category but the organizational urgency around actually addressing it, and the visibility of the gap between what organizations said they were doing and what they were actually doing.
For IT risk professionals, this moment represents an opportunity that is worth being direct about. Supply chain risk assessment is a discipline that requires exactly the combination of technology understanding and risk framework knowledge that CRISC validates. The organizations that are now scrambling to assess their supply chain exposure need people who can structure that assessment rigorously, communicate the findings in business terms, and help prioritize the risk response. That is a description of what CRISC-trained practitioners do.
The specific risk areas that supply chain incidents have highlighted are worth understanding clearly because they map to CRISC exam content in concrete ways.
Third-party software risk covers the Log4Shell scenario and the broader category of vulnerabilities introduced through open source components and commercial software. Assessing this risk requires understanding software composition, dependency management, and the controls that should exist around software acquisition and update processes. The CRISC domain on IT risk assessment covers the frameworks and methodologies for evaluating this category of risk systematically.
Managed service provider risk became prominent after the Kaseya ransomware attack, which compromised multiple managed service providers simultaneously and reached their downstream customers through trusted remote management connections. MSP relationships involve a specific pattern of elevated trust and access that creates a distinct risk profile. Auditing and managing that risk requires understanding both the technical access patterns involved and the contractual and governance mechanisms that should constrain them.
Software build and deployment pipeline integrity is the category that SolarWinds most directly addressed. The controls that should exist around software development, build, and release processes to prevent the insertion of malicious code into legitimate software are a legitimate audit and risk assessment domain that relatively few organizations had addressed rigorously before 2020.
ISACA has published guidance on supply chain risk management that supplements the CRISC curriculum and is worth reviewing. Their risk frameworks and governance resources are available at ISACA’s risk resources page.
The broader point is that the real-world events of the past two years have not created new categories of risk. They have illustrated the consequences of managing existing categories of risk inadequately. For risk professionals who understand those categories well, the increased organizational attention to supply chain risk translates into demand for the skills they have already developed. That is a genuine career tailwind and the CRISC is a meaningful way to signal that expertise.
Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.
