What is a Vendor Management Program?

Опубликовано: 05 Ноябрь 2024
на канале: Alexander C. Hubbard
766
16

What is a third-party or vendor management program? Often times you hire a vendor and they have something that touches your network, whether it be hardware, software or otherwise. These could be vendors that are critical to your organization's operations. They might even be well known vendors. But how do you know they are following security best practices? It's likely that you don't unless you have one of these programs established in your organization. On the surface, it's a program that says "every X number of years we're going to review your security documents." You're going to go to your vendor and say "hey I need to see your security documents, your SOC reports, ISO certs any kind of security documentation, white papers, anything that you have" - many large organizations will have an automated system in place to request these documents and audit them. You may have even received one of these questionnaires if your organization provides services to another organization.

https://achubbard.com
  / achsysadmin  
   / @thecybersecuritymindset  
  / ach_sysadmin  

#vciso #passwords #authentication #cybersecurity #cyberhygiene #cybersecurityawareness #cybersecuritydefinitions #achubbard #achsysadmin #ciso #security #it #sysadmin #systemadministration #systemadmin #itsecurity #itsec #infosec #informationsecurity #vendor #vendormangement #thirdparty