Third-Party Connectivity

Third-party connectivity introduced external systems into networks, requiring strict controls, monitoring, and agreements to manage trust and reduce security risks.

2 slides · 1 min read · Domain 4

Slide 1

To achieve efficiency in business operations, organizations often rely on third parties to provide connectivity services, or they enable third parties to directly connect to their infrastructures. While the technical issues related to interconnectivity (i.e., protocols and interfaces) present similar challenges to the issues already discussed, organizations that leverage third parties for connectivity services need to apply good management practices to these relationships, including the following:

  • Establish an organizational policy for creating, onboarding, monitoring, managing, and offboarding third-party connectivity relationships.
  • Inventory the existing third-party relationships, evaluating the relationship against the policy to identify relationships that pose greater risks to the organization.
  • Apply monitoring and auditing practices, consistent with contractual relationships, to third-party relationships.

When access is terminated, verify that the IAM environment reflects the removal of privileges, the physical and logical interconnections are indeed removed, and the organization has recovered all its physical property previously in the possession of the third party.

Test this domain