Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

9/1/2016
01:00 PM
Linn Freedman
Linn Freedman
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

3 Golden Rules For Managing Third-Party Security Risk

Rule 1: know where your data sets are, which vendors have access to the data, and what privacy and security measures are in place.

Third-party vendors have access to valuable, sensitive corporate and government data, yet more than one third of companies don’t believe these vendors would tell them if they had a data breach, according to a recent study from the Ponemon Institute.

Although it's common to include data privacy and security procedures in third-party contracts to ensure vendors have appropriate measures in place to protect company data, it is difficult to evaluate how the vendor is protecting data from unauthorized access, use, and disclosure, and to know whether the vendor has appropriate contractual terms in place with downstream, who may also have access to your data. 

This disconnect creates a high-risk area for all industries as more and more data loss through third-party vendors results in a breakdown of trust and communication. In the Ponemon survey, about half of 600 respondents who were familiar with their organization’s data practices confirmed that at least one of their vendors was the cause of a data breach, and an additional 16% didn’t even know that a breach had occurred. About 60% of respondents said they felt vulnerable because they were sharing sensitive data with third parties that might have weak security policies.

Golden Rule 1: Know where your data lives
Vendor management of data privacy and security is a key component of risk management. As a first rule, you have to know where your data sets are, which vendors have access to the data, and what privacy and security measures are in place to protect it.

Golden Rule 2: Remember Target
The second golden rule, exemplified by the infamous Target breach, is that data security depends on the weakest link in the chain. The 2013 data breach at Target rocked the world when an HVAC vendor in charge of the environmental controls at Target's retail stores was hacked. By gaining access to Target’s IT system credentials, the hacker found an open door to customer data, which was not segregated from its environmental data. Three years after the Target breach, 73% of the Ponemon survey respondents say cybersecurity incidents involving vendors are increasing.

Golden Rule 3: Develop a Plan
If you don’t know where your data sets are, where the data is being transferred, what your primary and downstream vendors are doing with it, or the security measures they have in place, you are overdue for a formal vendor management program. For a comprehensive approach, prepare to:

  • Map your vendors. Data mapping shows you where data resides in your own organization. Use a similar approach to map your vendors, to track who has access to your data, and to uncover areas of greatest risk.
  • Put one department in charge of vendor management. Ask your legal, finance, or compliance department, (not IT or infosec) to be responsible for vendor management. While IT should be involved to follow the data and map data flows to third-parties, an administrative department must oversee that vendor security measures are included in every contract and that internal groups are working together track data that leaves the organization
  • Put it in writing.  Specify in every vendor contract who, how, and why each vendor will access your data.
  • Use financial terms to enforce vendor compliance.  As a condition of doing business with you, a vendor must specify measures that protect the privacy and security of your data, and indemnify you against any breach or loss. It’s not worth the risk to work with a vendor that won’t sign a contract that includes these provisions.
  • Audit, audit, audit. Plan regular data security reviews with your vendors, and review your contractual provisions for trouble spots before they become a serious problem. Using security questionnaires is a common practice to audit vendors.

Companies can significantly reduce their risk of a catastrophic breach by staying a step ahead of the bad guys. The best data security approach includes rigorous risk assessment, prudent planning, consistent internal policies, and regular tracking and review of data access by your vendors and their vendor chain. It is possible to do this well. 

Related Content:

 

Linn Freedman is chair of the Data Privacy + Security practice at the law firm, Robinson+Cole, and is an adjunct professor in Brown University's Executive Master in Cybersecurity program, a program for mid-career professionals with increasing responsibility in cybersecurity. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Practical Privacy Coach
50%
50%
Practical Privacy Coach,
User Rank: Apprentice
9/6/2016 | 12:39:27 PM
Golden tips for all businesess
Great article - these 3 golden rules apply to all businesses - even clubs that we belong to.

If you collect information you are responsible for ensuring the safety and security of that information - especially when you hire third parties to help you do your work.

The more important or sensitive the information that you collect, the higher your standards should be for yourself, your internal and your external team.

Use these 3 golden rules as your starting platform to prevent a privacy breach. 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/28/2020
The Problem with Artificial Intelligence in Security
Dr. Leila Powell, Lead Security Data Scientist, Panaseer,  5/26/2020
10 iOS Security Tips to Lock Down Your iPhone
Kelly Sheridan, Staff Editor, Dark Reading,  5/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13693
PUBLISHED: 2020-05-29
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
CVE-2020-13173
PUBLISHED: 2020-05-28
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing...
CVE-2019-6342
PUBLISHED: 2020-05-28
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
CVE-2020-11082
PUBLISHED: 2020-05-28
In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1.
CVE-2020-5357
PUBLISHED: 2020-05-28
Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time wi...