Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

How to manage third-party risk in the supply chain

usscmc by usscmc
February 28, 2021
How to manage third-party risk in the supply chain
Share on FacebookShare on Twitter

The recent SolarWinds supply chain hack has affected public and private organizations worldwide, but this type of attack is not new. The Target, Home Depot, Boston Medical Center and PNI Digital Media data breaches are all instances where malicious actors took advantage of security weaknesses in the supply chain to compromise more heavily defended or more valuable networks.

Stolen login credentials, certificates and keys are often at the root of these attacks, enabling hackers to open the door to their smaller or less security-aware targets’ internal networks.

The SolarWinds incident shows, however, that even highly secure providers can be used as a steppingstone when extremely skilled hackers are involved. To mitigate this potent threat and other threats like it, every organization needs to learn how to manage third-party risk.

Here, learn what to expect and require from any third party connecting to enterprise systems to create a vetted and trusted security-aware supply chain.

Verify partners’ controls and certifications

Organizations must require subcontractors, vendors and supply chain partners to meet the certification requirements of appropriate compliance standards, such as ISO 27001, PCI DSS, HIPAA and ITAR. This will demonstrate that at least a certain level of IT security is being met.

Note, however, that gaining these accreditations may be too costly for smaller companies. In this case, their policies and practices should be contractually obliged to meet the organization’s own security standards. Asking for a System and Organization Controls 2 report is a good place to start, as it covers how a business oversees security, availability, processing integrity, confidentiality and privacy of a system.


Perform third-party risk assessments

Even with certifications and compliance standards assurances in place, a third-party risk assessment should be performed on each supplier to identify exactly which types of security controls and monitoring are required. An annual third-party audit should be conducted to ensure these controls are in place and working correctly. Where this is not possible, agree on a mechanism capable of monitoring compliance.

Image displaying supply chain attack example
A sample supply chain attack.

Be sure to make risk assessments information-driven rather than supplier-centric. This approach makes assessments easier to repeat across different vendors. Assign an assurance level to each application handling data. To determine the security controls required before access can be granted, base those assurances on business risk factors, such as sensitive information disclosure, personal safety, reputation damage, financial loss, operational risk and legal violations.

As stolen credentials are often used to gain a foothold in a network, multifactor authentication should be mandatory for access to any shared resources.

Map flow of traffic and critical data

Security teams must agree on a well-defined strategy that governs access to the organization’s internal resources. This should be based on the principle of least privilege and strictly map the flow of traffic and critical data to enable efficient monitoring of supplier access.

This monitoring should — at a minimum — be able to detect threats, unusual activity and data exfiltration. Network segmentation and compartmentalization, or the use of parallel networks to run supply chain applications, will also help to build a more resilient environment able to detect, deny and disrupt an attack.

With regard to data sharing, it is important to contractually agree on what information can be shared and with whom, as well as who maintains ownership of the data and what is considered acceptable use. In addition, all members of the supply chain should be required to encrypt data at rest and data in transit.

Additional steps

Beyond certifications, risk assessments and data management, security awareness training and social engineering assessments are also important to ensure all personnel in the supply chain have received appropriate training.

To be prepared for the worst, organizations can also periodically test off-site data backups and disaster recovery plans; this should include test scenarios with suppliers. Both parties must have a plan to notify the other if their network, systems or data have been compromised or if a breach is suspected so there can be a coordinated response.

Security is only as strong as the weakest link. While securing your supply chain may seem rather onerous, failure to do so could prove far more costly. Marriott’s failure to perform due diligence on its subsidiary Starwood’s IT infrastructure has been specifically singled out in litigation following a data breach that affected up to 500 million guests.

Supply chain and third-party risk management must be embedded within procurement and vendor management processes with clear metrics and service-level agreements governing application and data security. Although these steps will not guarantee complete security of sensitive data, they will make the supply chain stronger and the organization less likely to become the victim of a supply chain-based attack.

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2025 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2025 www.usscmc.com