Physical Validation Overview Flashcards
Overview
- Physical Validation Objectives
- Risk-Based Approach
- Program Design and Scope
- When to Perform an Onsite
*Gold standard of due diligence.
-The difference between asking if the room is clean vs. checking to see if the room is clean.
Physical Validations:
Objectives
Who?
-Vendors that you need to spend time on.
-Your high risk vendors
-It takes time, yours and the vendors so make sure you’re spending resources correctly.
How?
-Virtual vis on sight.
Virtual with a collab tool
What?
-What are you going to be asking?
-What’s your scope?
-Does the vendor have their own data center or using a CSP like google, google cloud, AWS?
Where?
-Where are you going to be?
-Company headquarters?
-Manufacturing site?
-Data center?
Data center is often separate from the headquarters
Physical Validation Risk-Based Approach
-Amount of Effort
-Criteria
-Cadence and Repeats
Physical Validation Risk-Based Approach:
Amount of Effort
-Some organizations are extensive in their research
- Typically for Greg, he does 2 days and 1-2 people
Physical Validation Risk-Based Approach:
Criteria
-When does a vendor require physical validation.
Systemically critical vendors on entry
Because of the value of physical validation, might be beneficial to do a physical validation rather than virtual questionnaire.
Physical Validation Risk-Based Approach:
Cadence
-How often are you going back to reevaluate?
Should be clearly defined
Risk based
Vendors that have been breached
High risk vendors with high significant findings annual or every other year
Physical Validations:
Objectives:
Who?
How?
What?
Where?
Physical Validations:
Objectives:
Who?
Who
-Vendors that you need to spend time on.
-Your high risk vendors
-It takes time, yours and the vendors so make sure you’re spending resources correctly
Physical Validations:
Objectives:
How?
How
-Virtual vs on sight.
-Virtual with a collab tool
Physical Validations:
Objectives:
What?
What
-What are you going to be asking?
-What’s your scope?
-Does the vendor have their own data center or using a CSP like google, google cloud, AWS?
Physical Validations:
Objectives:
Where?
Where
-Where are you going to be going?
-Company headquarters? Manufacturing site? Data center?
Data center is often separate from the headquarters