While one could argue for considering and assessing all third-parties or vendors, I recommend applying a risk-based approach to ensure the program’s effectiveness and practicality. Similar to the IT Asset portfolio, establishing a vendor portfolio with essential information is advisable. IT GRC does not necessarily need to maintain a system of record for vendors, as this responsibility typically falls under legal or procurement functions. However, IT GRC should maintain a repository of relevant information to understand the landscape and potential threats posed by external resources and avenues.
It’s crucial to ensure that this information is current and to conduct litmus tests to identify critical vendors from an IT GRC perspective. Critical vendors in this context are those that handle, process, or store proprietary information belonging to the Organization. You can incorporate the litmus test into a comprehensive Business Impact Assessment or conduct them separately, assessing criticality based on factors such as dependency, the classification of information handled by the vendor, the vendor’s overall security posture, etc.
Leave a Reply