06. Management of External Services (332) Flashcards
TPRM
Third Party Risk Management activities are used to discover and manage risks associated with external third parties
332
TPRM
Security managers should consult with several stakeholders in teh organisation to identify subsets of third parties. Stakeholders include;
- Legal
- Procurement
- Accounts payable
- Information Technology
- Facilities
- Department heads and business unit leaders
- Location specific leaders
337
TPRM Life Cycle
Managing business relationships with third parties is a life cycle process;
Initial assessment
Third party suitability assessment
Onboarding
Beginning business relationship, estbalish risk level criteria
Legal Agreement
Legal agreements finalised
339
RIsk Tiering and Vendor Classification
- Not possible in large organisations to perform due dilligence on all third party vendors.
- Organisations should apply a risk based approach and classify vendors according to risk level
- Examples of vendor classification;
Volume of sensitive customer data
Amount of customer sensitive data
Volume of sensitive internal data
Amount of sensitive internal data
Operational criticality
How much does organisation depend on the vendor for day to day operations
Physical access
Degree to which vendor has phsycal access ot organisations infromation processing centers
Access to systems
Ability of third party to access information systems.
Contractual obligations
Requirements to maintain security program as part of contract
342
Assessing Thirt Parties
Techniques to assess third parties;
- Questionnaires
- Questionnaire confirmation
- Site visit
- External attestations
- External business intelligence
- External cyber intelligence
- Security scans and penetration tests
- Intrusive monitoring
344
Questionnaires and Evidence
Sending qustionnaire to third party periodically with request to answer questions and provide specific artifcts to serve as evidence to responses
346
Proactive Issue Remediation
Risks of outsourcing to third parties can be remedied through contract provisioning;
- Service Level Agreements
- Quality
- Security Policy and Controls
- Business Continuity
- Employee Integrity
- Ownership of intellectual property
- Roles and Responsibilities
- Schedule
- Regulation
- Warranty
- Dispute and resolution
- Payment
347