Packet Flipper
Third-party risk

Third-party risk

This objective covers Third-Party Risk Management (TPRM). Modern organizations rarely operate in isolation; they rely on external SaaS providers, cloud vendors, and physical suppliers. However, when you share data or network access with a third party, their security vulnerabilities become your security risks.

1. Vendor Assessment: Verifying Third-Party Security

Before handing over sensitive data or connecting networks, an organization must thoroughly assess a vendor’s security posture.

  • Independent Assessments: Relying on audited, third-party validations of a vendor’s controls. The gold standard here is a SOC 2 Type II report (Service Organization Control), which evaluates a vendor’s security, confidentiality, and availability over an extended monitoring period (typically 6-12 months), proving their controls actually work over time.
  • Evidence of Internal Audits: Reviewing the vendor’s own internal documentation, self-assessments, and policy compliance records.
  • Penetration Testing: Requesting the executive summary of the vendor’s latest third-party penetration test to ensure external attackers cannot easily breach their infrastructure.
  • Right-to-Audit Clause: A critical contractual provision that grants your organization the legal right to review the vendor’s security books, inspect their physical data centers, or conduct vulnerability scans of their services to verify compliance.
  • Questionnaires: Standardized, self-reported security assessments sent to vendors (such as the SIG/Standardized Information Gathering questionnaire) asking detailed questions about their encryption, access controls, and incident response procedures.
  • Supply Chain Analysis: Evaluating the risk of downstream dependencies. For example, if you hire a software vendor, you must analyze their suppliers and developers to ensure that malicious code isn’t injected through an unvetted open-source library or an offshore contractor.

2. Vendor Selection: Due Diligence & Ethics

During the sourcing phase, organizations must conduct rigorous evaluations to prevent financial, legal, or reputational fallout.

  • Due Diligence: The overarching process of investigation and verification. It ensures a vendor is financially stable, legally compliant, and technically capable of protecting your assets before a formal relationship begins.
  • Conflict of Interest: Identifying situations in which an internal decision-maker has a competing professional or personal interest in a vendor (e.g., an IT director awarding a major software contract to a company owned by a family member), which could compromise objective risk assessment.

3. Agreement Types: Structuring the Legal Framework

CompTIA rigorously tests the distinctions between corporate agreements. You must know which document to deploy based on the scenario.

Agreement TypeWhat it Does / Key Purpose
Non-Disclosure Agreement (NDA)Protects sensitive data; legally binds both parties to keeping proprietary information, source code, or trade secrets confidential during talks or operations.
Service-Level Agreement (SLA)Defines strict, measurable technical performance metrics (e.g., “The cloud service must guarantee 99.99% uptime”) along with clear financial penalties if the vendor fails to meet them.
Master Service Agreement (MSA)An overarching governance contract that governs long-term relationships. It lays down foundational terms (indemnification, intellectual property, payment terms) so future projects don’t have to renegotiate them from scratch.
Statement of Work (SOW) / Work OrderA highly specific addendum attached to an MSA that details the explicit deliverables, milestones, timelines, and hourly rates for a single, distinct project.
Memorandum of Understanding (MOU)A formal, non-binding document outlining a mutual intent or shared blueprint between parties. It lacks the legal teeth of a contract but aligns high-level expectations.
Memorandum of Agreement (MOA)A step closer to a legal contract than an MOU. It outlines specific, conditional actions both parties agree to take to achieve a common goal (e.g., “If Party A provides X, Party B will perform Y”).
Business Partners Agreement (BPA)A legally binding contract between co-owners or close business partners that details equity shares, profit/loss distribution, decision-making powers, and what happens if a partner leaves the venture.

4. Vendor Monitoring & Rules of Engagement

Managing third-party risk is a continuous operational cycle, not a one-time onboarding checkpoint.

  • Vendor Monitoring: Continually evaluating performance and security throughout the relationship. This involves tracking SLA compliance, reviewing updated SOC 2 reports annually, monitoring threat intelligence feeds for news of vendor data breaches, and ensuring user access is instantly revoked during offboarding.
  • Rules of Engagement (RoE): A highly structured document detailing the exact technical boundaries, timelines, approved testing targets, and forbidden techniques allowed when conducting security assessments or penetration tests against a third party’s environment. The RoE ensures that security vetting activities do not accidentally crash a production system or violate data privacy bounds.