Designing a 3rd party Risk Management Program

No ratings

Presented at BSidesTampa 2020 by

Provides practical advice to design a TPRM program. Details the end-to-end process: identify, risk rank, assess, risk treatment, monitor and oversight and; escalations. Includes options based on risk tolerance and available funding: - Provides security requirements for vendor contract templates. - Describes how to identify new and existing vendors through existing Supply Chain Management processes and in organizations where it is necessary to leverage financial systems. Includes examples where vendors may slip through the cracks. - Addresses a risk-based approach to tier vendors for assessment when confidentiality and business criticality information is available. Otherwise, includes alternatives such as risky vendor categories and tiering questions. - Assessment options include on-site assessment, questionnaires, artifact reviews, vulnerability scans and acceptance of independent assessments and; certifications. - Describes risk treatment: tracking remediation to closure, policy exceptions and risk register entries. - Provides recommendations to reduce residual risk when vendor service is discontinued. - Addresses program architecture: welcome packet, process diagram, procedures manual, message templates, system of record, reporting, metrics, etc. - Includes tips to develop a roadmap to mature the program over three years. - Provides examples that can be leveraged in small, medium and large organizations. Includes real world challenges with recommendations for processes.