click below
click below
Normal Size Small Size show me how
third-party vendor
third-party vendor risks
| Question | Answer |
|---|---|
| Managed Service providers | Organizations that provide a range of technology services and support to businesses and other clients |
| Supply chain attack | Attack that involves targeting a weaker link in the supply chain to gain access to a primary target |
| CHIPS Acts | US Federal statue that provides roughly $280 billion and new funding to boost research and manufacturing of semiconductors inside the United States |
| Semiconductors | Essential components in a wide range of products, from smart phones, and cars to medical devices and defense systems |
| how to safeguard against supply chain attacks | vendor due diligence, regular monitoring and audits, education and collaboration, incorporating contractual safeguards |
| vendor assessment | Process that organizations implement to evaluate the security, reliability, and performance of external entities |
| vendors | Businesses or individuals that provide goods or services to an organization |
| Suppliers | Individuals involved in the production and delivery of products or parts of products |
| Penetration testing | Simulated cyber attack against the supplier system to check for exploitable vulnerabilities |
| Internal audit | Vendor self assessment where they evaluate their own practices against industry, standards or organizational requirements |
| Independent assessment | Evaluation conducted by third-party entities that have no stake in the organizations or vendors operations |
| Supply chain analysis | Used to dive deep into a vendors entire supply chain and assess the security and reliability of each link |
| Vendor assessment | Process that organizations implement to evaluate the security, reliability, and performance of external entities |
| Due diligence | Rigorous evaluation that goes beyond surface level credentials |
| Conflict of interest | Arises when personal or financial relationships could potentially cloud the judgment of individuals involved in vendor selection |
| Vendor questionnaires | Comprehensive documents that potential vendors fill out to offer insights into the operations, capabilities, and compliance |
| Rules of engagement | Guidelines that dictate the terms of interaction between an organization and its potential vendors |
| Monitoring | Mechanism to ensure that the chosen vendors still aligns with the organizational needs and standards |
| Feedback loops | Involve a two-way communication channel where both the organization and the vendor share feedback |
| Business contracts | , Service level agreement (SLA), memorandum of agreement (MOA), memorandum of understanding (MOU), master service agreement (MSA), statement of work (SOW), non-disclosure agreement (NDA), business partnership agreement (BPA) |
| Basic contract | Versatile tool that formally establishes a relationship between two parties |
| Service level agreement (SLA) | The standard of service a client can expect from a provider |
| Master service agreement (MSA) | Blanket agreement that covers the general terms of engagement between parties across multiple transactions |
| Statement of work (SOW) | Used to specify details for a particular project |
| Non-disclosure agreement (NDA) | Commitment to privacy that ensures that any sensitive information shared during negotiations remains confidential between both parties |
| Business partnership agreement (BPA) | Document that goes a step beyond the basic contract when two entities decide to pull their resources for mutual benefits |