Assessing those you depend on.
WHY IT MATTERS
Compromise frequently arrives through suppliers with access to your systems or data.
WHAT TO ESTABLISH ABOUT ANY SUPPLIER WITH ACCESS
What access they have What data they hold What their security arrangements are Whether they are assessed
WHAT TO REQUEST
Evidence of their security practices Assessment or certification, where applicable Confirmation of how they protect your data
WHY EVIDENCE RATHER THAN ASSURANCE
Assertions cost nothing.
WHAT TO ESTABLISH IN AGREEMENTS
Security requirements Notification of incidents affecting you Right to assess or receive assessment results Restrictions on subcontracting What happens at termination
WHY INCIDENT NOTIFICATION
You cannot respond to a breach at a supplier you are not told about.
WHAT TO ESTABLISH
Notification within a defined period.
WHAT TO LIMIT
Their access, to what is necessary.
WHY
Supplier access is frequently far broader than required.
WHAT TO REVIEW
Who has access, periodically.
WHAT TO REMOVE
Access for suppliers no longer engaged.
WHY
It is the standard failure and it persists indefinitely.
WHAT TO ESTABLISH ABOUT SOFTWARE SUPPLIERS
Their practices for security in development How they handle vulnerabilities How quickly they release fixes
WHAT TO ASK
How to report a vulnerability to them.
WHY
Suppliers with no route for reports do not fix things.
WHAT TO ESTABLISH ABOUT YOUR OWN OBLIGATIONS
What your customers require of you.
WHY
You are someone else's supplier.