How is your company managing the security of your vendors?
According to the 2018 Ponemon Institute Data Risk in the Third-Party Ecosystem study:59% of companies have experienced a data breach caused by one of their vendors or third parties.Do you know how much is at stake if one of your vendors or fourth parties is breached? Security questionnaires are opportunities to understand the scope of your vendor's security controls.
Creating security questionnaires is an art
Each crafted question can strengthen your vendor management program. The questions you ask are not one-and-done types of deals. Each answer should be an indicator of how you should evaluate your vendors’ security programs. Not asking your vendor the right questions can introduce more risks for your company. Here are the security areas you should address in your security questionnaires: Stance on Compliance How is the vendor establishing information assurance with their clients? This area addresses the vendor's efforts in maintaining security compliance. With the growth of privacy laws (GDPR, CCPA, etc.), your clients will demand your company be compliant in all areas which include your vendors. Vendors following established security standards (like SOC 2, ISO, PCI, HITRUST, etc.) can provide the assurance that they are following best practices on an annual basis. Risk Management Program The next area you should address is the vendor’s internal and external risk assessments. What vendor risks could your company be exposed to? Risk registers can provide your company with valuable insights from the vendor’s risk assessments. This is an opportunity to address the risks that impact your company's services and the steps taken by the vendor to treat them. Access Management What controls does the vendor have in place for access provisioning, review, and de-provisioning of accounts with access to your company data? You should determine if the least-privilege method is applied to accounts with access to your company data. Not every user at the vendor should be a super admin and managing the every service for your company. Once accounts are established, evaluate how the vendor will review access to ensure each access level is appropriate. Incident Management When there is an incident on the vendor side, how and when will your company be informed? Inspect the vendor’s Incident Response Policy to determine how your company will be involved during these events. Based on the answers in this section, your Incident Response Policy should be updated based on the vendor's procedures. Service Availability What security controls are in place to monitor and ensure service level agreements are met? This is a chance for your company to understand the redundancy controls that are in place. Additionally, your company gets the chance to understand the vendor’s history of breaches and the actions the vendor took to manage their service level agreements. The actions taken should reflect what the vendor’s Business Continuity & Disaster Recovery Program mandates. Patch Management What is the vendor’s process of notifying your company of the requirements and timeline for critical patch deployment? There are two risks to consider in applying patches:- Not having the latest version could leave your company exposed to vulnerabilities
- Not testing the patches properly before deployment could impact your company’s service availability
Contact Us
Creating security questionnaires is an art and a continuous effort, but you do not have do it alone. Reach out to our team to help you ask the right questions to your vendors!
Jack Nguyen
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)