Third-party Risk Assessment
- •
def
- •
evaluating the security risk introduced by working with external vendors, since every organization works with vendors who may share company data
- •
- •
activities
- •
categorize and manage risk by vendor; use contracts to set clear, enforceable expectations
- •
Right-to-Audit Clause — a contractual guarantee allowing a security audit of the vendor at any time
- •
evidence of internal audits — a third party evaluates the effectiveness of vendor security controls, often for compliance
- •
supply chain analysis — evaluating coordination and IT systems across the whole path from supplier to customer
- •
independent assessments — bringing in outside specialists to evaluate security and offer recommendations
- •
vendor selection due diligence — checking a company's financial status and legal history before doing business, watching for conflicts of interest
- •
vendor monitoring — ongoing review after the contract is signed (financial health, IT security posture, news/social media), typically assigned to a specific person
- •
questionnaires — direct security questions to the vendor, used to update the vendor risk analysis over time
- •
- •
related