Knowledgebase

Managing Third-Party and Supplier Security Print

  • 0

Assessing those you depend on.

WHY IT MATTERS

Compromise frequently arrives through suppliers with access to your systems or data.

WHAT TO ESTABLISH ABOUT ANY SUPPLIER WITH ACCESS

What access they have What data they hold What their security arrangements are Whether they are assessed

WHAT TO REQUEST

Evidence of their security practices Assessment or certification, where applicable Confirmation of how they protect your data

WHY EVIDENCE RATHER THAN ASSURANCE

Assertions cost nothing.

WHAT TO ESTABLISH IN AGREEMENTS

Security requirements Notification of incidents affecting you Right to assess or receive assessment results Restrictions on subcontracting What happens at termination

WHY INCIDENT NOTIFICATION

You cannot respond to a breach at a supplier you are not told about.

WHAT TO ESTABLISH

Notification within a defined period.

WHAT TO LIMIT

Their access, to what is necessary.

WHY

Supplier access is frequently far broader than required.

WHAT TO REVIEW

Who has access, periodically.

WHAT TO REMOVE

Access for suppliers no longer engaged.

WHY

It is the standard failure and it persists indefinitely.

WHAT TO ESTABLISH ABOUT SOFTWARE SUPPLIERS

Their practices for security in development How they handle vulnerabilities How quickly they release fixes

WHAT TO ASK

How to report a vulnerability to them.

WHY

Suppliers with no route for reports do not fix things.

WHAT TO ESTABLISH ABOUT YOUR OWN OBLIGATIONS

What your customers require of you.

WHY

You are someone else's supplier.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot