Vendor Risk Management: Ten Frequently Asked Questions

Email     |     Share  
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12
Next Vendor Risk Management: Ten Frequently Asked Questions-2 Next

Timing

How long does it take to implement a VRM program?

This, of course, is variable. The first step you'll want to take when developing a vendor risk management program is to create a strategy. Once you have that in place, you can determine which method(s) you'll use to monitor your vendors' security positions. You have to determine which of your vendors present the most risk — in other words, which vendors have access to the most sensitive data — so that you can prioritize which vendors need monitoring based on level of risk. If you have a thousand vendors, but only 10 have access to your network or other sensitive information, you're going to want to know that.

This process, albeit critical, isn't easy or fast. If you're the person tasked with creating a list of these vendors, you'll have to first find the lists (keeping in mind that there are probably many lists throughout the organization), and then figure out how important each one is. You typically base this on conversations with different departments, or by researching what the vendor is actually doing for you. This process could take weeks or months.

After you've created your strategy, you'll need to review your existing contracts. This is a very lengthy process — it can also take weeks or months. Questionnaires can take a large chunk of time as well — you have to develop one (which can be done in-house, through a consultant, or via an option like Shared Assessments), send it to your vendor, give them time to fill it out, and then review it. Once you've sent it to your vendor, you can give them a time frame for completion, for example two weeks or two months.

As cyber threats become more sophisticated and complex, businesses need not only to ensure they are secure, but that their vital partners, suppliers and vendors are protecting themselves as well. According to the 2015 Verizon DBIR, 70 percent of observed cyber attacks involved a secondary victim. To avoid being blindsided, organizations are beginning to monitor the security of their third parties to reduce the likelihood of a data breach.

Gartner estimates that around 10 percent of companies have formalized IT risk management programs, but that the figure will grow to 40 percent by 2018. If you're just beginning to implement a vendor risk management (VRM) program, BitSight Technologies has identified 10 frequently asked questions to help you get started.

 

Related Topics : Unisys, Stimulus Package, Security Breaches, Symantec, Electronic Surveillance

 
More Slideshows

BitSightRansomware0x Ransomware: The Rising Face of Cybercrime

Ransomware is a legitimate threat, with estimates from the U.S. Department of Justice showing that over 4,000 of these attacks have occurred every day since the beginning of the year. ...  More >>

Security121-190x128 5 Ways CFOs Can Implement an Effective Cybersecurity Strategy

While cybersecurity concerns are widespread, finance remains one of the most vulnerable areas for malicious attacks. ...  More >>

infra100-190x128 Top 10 Strategic Technology Trends for 2017

Here are the top 10 strategic technology trends that will impact most organizations in 2017. Strategic technology trends are defined as those with substantial disruptive potential or those reaching the tipping point over the next five years. ...  More >>

Subscribe to our Newsletters

Sign up now and get the best business technology insights direct to your inbox.