Third-party Audit and Assessment

Gay

2 slides · 1 min read · Domain 6

Slide 1

Third-party relationships can cover a wide range of activities involving supply chains and service providers. Cloud services providers (CSPs), Internet Service Providers (ISPs), managed security services providers, consultants, and advisors are all broadly classified as service providers.

Hardware and software vendors, including

The terms and conditions of these contracts should establish the working other organizations developing software, data, or documentation expressly for an relationships necessary to jointly organization are providing products, and determine responsibilities for both are more appropriately considered as security and compliance assessment part of the supply chain that enables the and audit activities; if they do not, that gap needs to be resolved and the contracts organization to function properly. possibly renegotiated. Two different processes should drive an organization to identify and review all of the

In some cases, third parties may have third parties they have direct contracts or additional relationships with other other arrangements with, and characterize organizations, either their own service these in terms of risk, compliance providers or as clients they provide services to. In either case, the first party (the requirements, or both. organization that a security professional would be advising or working for) needs to identify which poses what mix of risk or compliance concerns and resolve these with the third party.

Test this domain