Third-Party Assessments and Monitoring
3 slides · 2 min read · Domain 1
Third-Party Assessments and Monitoring
It is imperative that an organization apply the same risk-management methodologies and perspectives to its supply chain as the organization did for its own internal operations.
This may include the organization performing the following for each entity within the supply chain:
GOVERNANCE REVIEW
FORMAL SECURITY AUDIT
SITE SECURITY SURVEY
PENETRATION TESTING
However, in many cases, this is untenable, and sometimes it can create additional liability issues for both parties. Instead, organizations often rely on audit reports prepared by certified third parties to properly evaluate the entities within the organization's supply chain.
This has notably been the case with managed cloud services, where the cloud customer often does not even know the | physical location of the cloud data center and must rely on external validation of the provider's security.
There are a variety of standards • AICPASSAE 16 SOC reports
The American Institute of Certified
and audit methodologies
Public Accountants (AICPA) created
for assessing the security of
the Statement on Standards of external organizations.
Attestation Engagements (SSAE) 16 These include but are not standard as a response to prevailing federal legislation in the United limited to the following:
States (specifically, the SarbanesOxley Act, referred to as SOX). The SSAE 16 standard details three types
- CSA STAR evaluation: As mentioned
of reports intended for different uses;
previously, the Cloud Security Alliance these are the SOC reports. The SSAE offers a registration program for cloud
20 SOC 1,2,3 are highly regarded providers called STAR. It can be selfassurance reports. While the SSAE 16 administered by the target organization standard is designed for publicly traded or conducted by a certified external corporations, it has come into wide use auditor, depending on the STAR Level by organizations of all types.
the target organization seeks.
- ISO-certified audits: Each ISO standard can be assessed by an accredited auditor, and the target organization can earn certification by successfully passing this audit.
