Defining Third-parties or Vendors from IT GRC perspective

While one could argue for considering and assessing all third-parties or vendors, I recommend applying a risk-based approach to ensure the program’s effectiveness and practicality. Similar to the IT Asset portfolio, establishing a vendor portfolio with essential information is advisable. IT GRC does not necessarily need to maintain a system of record for vendors, as this responsibility typically falls under legal or procurement functions. However, IT GRC should maintain a repository of relevant information to understand the landscape and potential threats posed by external resources and avenues.

It’s crucial to ensure that this information is current and to conduct litmus tests to identify critical vendors from an IT GRC perspective. Critical vendors in this context are those that handle, process, or store proprietary information belonging to the Organization. You can incorporate the litmus test into a comprehensive Business Impact Assessment or conduct them separately, assessing criticality based on factors such as dependency, the classification of information handled by the vendor, the vendor’s overall security posture, etc.


Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from CSO Tips

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from CSO Tips

Subscribe now to keep reading and get access to the full archive.

Continue reading