Vendor risk management is top of everyone’s mind considering recent headline grabbing supply chain attacks, such as SolarWinds.
But as more vendors enter your digital supply chain, keeping up with vendor adoption is tough. According to Accenture, 79 percent of businesses are adopting technologies faster than they can address related security issues.
For your organization to be truly protected against supply chain cyber risks, you must develop a robust vendor risk management (VRM) program. Start by creating a vendor risk management checklist that ensures you capture relevant information from your vendors during the onboarding process.
Here’s what to include:
1. Vendor risk assessment protocols
✔ Has a documented risk assessment policy and methodology that identifies and priorities digital assets.
✔ Has a vulnerability detection and management policy.
✔ Assesses and implements security controls based on emerging risks and threats.
✔ Assesses the likelihood of cyber threats and scenarios on a regular basis.
✔ Uses security questionnaires to assess risk in its own supply chain.
2. Vendor security protocols
✔ Has provided minimum requirements for network security, access controls (including remote access), and data security.
✔ Has documented practices for security hygiene, including software patching and configuration management.
✔ Conducts external and internal tests to identify vulnerabilities and attack vectors, including penetration testing—ask for the results of those tests.
✔ Continuously assesses the performance of security controls.
✔ Has documented security training plans for employees who handle and safeguard sensitive information.
✔ Has physical security procedures for offices and data centers, including visitor handling, access to premises, and surveillance.