1
00:00:00,090 --> 00:00:00,930
In this lesson,

2
00:00:00,930 --> 00:00:03,030
we're going to cover vendor assessments.

3
00:00:03,030 --> 00:00:05,250
Now a vendor assessment is an essential process

4
00:00:05,250 --> 00:00:07,860
that organizations implement to evaluate the security,

5
00:00:07,860 --> 00:00:10,650
reliability, and performance of external entities

6
00:00:10,650 --> 00:00:12,000
that they rely upon.

7
00:00:12,000 --> 00:00:14,160
In today's interconnected business landscape,

8
00:00:14,160 --> 00:00:16,770
a weak link in one vendor can have reverberations

9
00:00:16,770 --> 00:00:18,120
across multiple businesses

10
00:00:18,120 --> 00:00:19,710
and lead to widespread vulnerabilities

11
00:00:19,710 --> 00:00:21,570
and potential data breaches.

12
00:00:21,570 --> 00:00:24,150
Now, first, let's classify the primary entities

13
00:00:24,150 --> 00:00:26,640
that are often under the purview of vendor assessment.

14
00:00:26,640 --> 00:00:28,470
This includes vendors, suppliers,

15
00:00:28,470 --> 00:00:31,620
and managed service providers known as MSPs.

16
00:00:31,620 --> 00:00:34,170
Now, vendors are typically businesses or individuals

17
00:00:34,170 --> 00:00:36,540
that provide goods or services to an organization.

18
00:00:36,540 --> 00:00:39,120
Think of software providers, like Microsoft or Oracle,

19
00:00:39,120 --> 00:00:40,590
which your organization might rely on

20
00:00:40,590 --> 00:00:41,760
for an enterprise solution.

21
00:00:41,760 --> 00:00:43,620
Next, we have suppliers,

22
00:00:43,620 --> 00:00:45,420
and suppliers are typically going to be involved

23
00:00:45,420 --> 00:00:46,680
in the production and delivery

24
00:00:46,680 --> 00:00:48,840
of products or parts of products.

25
00:00:48,840 --> 00:00:50,910
For instance, a computer manufacturer

26
00:00:50,910 --> 00:00:52,410
might have multiple suppliers,

27
00:00:52,410 --> 00:00:55,140
with one providing processors, another providing memory,

28
00:00:55,140 --> 00:00:57,570
another providing hard drives, and things like that.

29
00:00:57,570 --> 00:00:59,280
Now, finally, we have MSPs,

30
00:00:59,280 --> 00:01:01,140
known as managed service providers.

31
00:01:01,140 --> 00:01:02,700
These are going to be hired by a company

32
00:01:02,700 --> 00:01:05,700
to manage IT services on behalf of your company.

33
00:01:05,700 --> 00:01:08,610
Now, a good example of an MSP, or managed service provider,

34
00:01:08,610 --> 00:01:11,820
would be a cloud service provider, like AWS or Google Cloud,

35
00:01:11,820 --> 00:01:12,653
and they're going to be used

36
00:01:12,653 --> 00:01:14,220
to manage vast data infrastructures

37
00:01:14,220 --> 00:01:16,110
so your organization can instead focus

38
00:01:16,110 --> 00:01:17,640
on their core competencies.

39
00:01:17,640 --> 00:01:20,130
Now, one vital aspect of the vendor assessment process

40
00:01:20,130 --> 00:01:22,740
is penetration testing of your suppliers.

41
00:01:22,740 --> 00:01:25,620
Penetration testing is essentially a simulated cyberattack

42
00:01:25,620 --> 00:01:27,090
against your supplier systems

43
00:01:27,090 --> 00:01:29,370
to check for exploitable vulnerabilities.

44
00:01:29,370 --> 00:01:31,290
Let's imagine your company sources its software

45
00:01:31,290 --> 00:01:32,880
from a third-party developer.

46
00:01:32,880 --> 00:01:35,130
Penetration testing the software would mean attempting

47
00:01:35,130 --> 00:01:36,810
to find and exploit vulnerabilities,

48
00:01:36,810 --> 00:01:38,850
just like an actual cyberattacker would,

49
00:01:38,850 --> 00:01:41,700
in order to attempt their own attacks against your network.

50
00:01:41,700 --> 00:01:44,490
Now, if a vulnerability is found, this is an indication

51
00:01:44,490 --> 00:01:45,780
that the software could be a risk

52
00:01:45,780 --> 00:01:48,240
to your organization's cybersecurity posture.

53
00:01:48,240 --> 00:01:50,190
Our goal with conducting a penetration test

54
00:01:50,190 --> 00:01:52,680
is really to validate that our service provider, or vendor,

55
00:01:52,680 --> 00:01:55,170
is taking their own cybersecurity posture seriously

56
00:01:55,170 --> 00:01:57,510
since their risks could become your risk

57
00:01:57,510 --> 00:01:59,910
once you install their software into your network.

58
00:01:59,910 --> 00:02:01,950
Now, when conducting your vendor assessments,

59
00:02:01,950 --> 00:02:04,020
one part of that is to review your contract

60
00:02:04,020 --> 00:02:05,880
with the vendor or service provider.

61
00:02:05,880 --> 00:02:08,160
When you're reviewing the contract, you should verify

62
00:02:08,160 --> 00:02:10,620
that you have a right to audit clause included inside

63
00:02:10,620 --> 00:02:11,790
of that contract.

64
00:02:11,790 --> 00:02:13,230
Now, this right to audit clause

65
00:02:13,230 --> 00:02:14,820
is going to grant your organization the right

66
00:02:14,820 --> 00:02:17,130
to evaluate the vendor's internal processes

67
00:02:17,130 --> 00:02:18,360
and ensure that they're in compliance

68
00:02:18,360 --> 00:02:19,980
with the agreed upon standards.

69
00:02:19,980 --> 00:02:23,220
For instance, if a company contracts a data management firm

70
00:02:23,220 --> 00:02:24,690
to handle its customer data,

71
00:02:24,690 --> 00:02:26,640
the right to audit clause would allow the company

72
00:02:26,640 --> 00:02:28,830
to periodically inspect the data handling,

73
00:02:28,830 --> 00:02:30,750
storage, and protection practices

74
00:02:30,750 --> 00:02:32,490
of the given vendor you've selected.

75
00:02:32,490 --> 00:02:34,320
Now, this isn't about a lack of trust,

76
00:02:34,320 --> 00:02:36,600
but rather, a method to ensure transparency

77
00:02:36,600 --> 00:02:39,300
and make sure that they're adhering to the best practices.

78
00:02:39,300 --> 00:02:41,220
Remember, inside of cybersecurity,

79
00:02:41,220 --> 00:02:43,470
we always want to trust but verify.

80
00:02:43,470 --> 00:02:45,390
Now, another element that instills confidence

81
00:02:45,390 --> 00:02:47,040
in vendor security is evidence

82
00:02:47,040 --> 00:02:49,050
of internal audits being conducted.

83
00:02:49,050 --> 00:02:51,810
An internal audit refers to a vendor's self-assessment,

84
00:02:51,810 --> 00:02:53,400
where they evaluate their own practices

85
00:02:53,400 --> 00:02:56,490
against industry standards or organizational requirements.

86
00:02:56,490 --> 00:02:58,410
For example, a cloud service provider

87
00:02:58,410 --> 00:03:00,780
might regularly audit its data protection measures

88
00:03:00,780 --> 00:03:02,850
to ensure that encryption protocols are up-to-date

89
00:03:02,850 --> 00:03:04,380
and effectively implemented.

90
00:03:04,380 --> 00:03:06,060
Now, when a vendor can present evidence

91
00:03:06,060 --> 00:03:08,310
of consistent and comprehensive internal audits,

92
00:03:08,310 --> 00:03:10,350
this does serve as a testament to their commitment

93
00:03:10,350 --> 00:03:12,330
to security and quality.

94
00:03:12,330 --> 00:03:14,370
Now, while internal audits are commendable,

95
00:03:14,370 --> 00:03:16,320
they may sometimes be insufficient,

96
00:03:16,320 --> 00:03:18,840
especially if you're lacking the rigor involved with them.

97
00:03:18,840 --> 00:03:19,673
This is where the need

98
00:03:19,673 --> 00:03:21,960
for an independent assessment will come into play.

99
00:03:21,960 --> 00:03:24,270
Independent assessments are evaluations conducted

100
00:03:24,270 --> 00:03:26,400
by third-party entities who have no stake

101
00:03:26,400 --> 00:03:28,920
in the organization or vendor's operations.

102
00:03:28,920 --> 00:03:30,660
Think about this as a neutral party

103
00:03:30,660 --> 00:03:32,820
who's going to be coming in to make sure the vendor is adhering

104
00:03:32,820 --> 00:03:34,620
to the security or performance standards

105
00:03:34,620 --> 00:03:36,240
that you both have agreed to.

106
00:03:36,240 --> 00:03:37,650
Let's consider there's a data center

107
00:03:37,650 --> 00:03:40,740
that houses critical information for multiple organizations.

108
00:03:40,740 --> 00:03:41,670
An independent body,

109
00:03:41,670 --> 00:03:44,610
like the International Organization for Standards, or ISO,

110
00:03:44,610 --> 00:03:46,440
might assess the data center's practices

111
00:03:46,440 --> 00:03:48,690
against its global standards to ensure they're meeting

112
00:03:48,690 --> 00:03:50,490
or surpassing the benchmarks.

113
00:03:50,490 --> 00:03:53,040
This third-party validation is going to be invaluable

114
00:03:53,040 --> 00:03:54,300
for organizations who aim

115
00:03:54,300 --> 00:03:56,310
to minimize their exposure to risk.

116
00:03:56,310 --> 00:03:58,620
Finally, in our discussion of vendor assessments,

117
00:03:58,620 --> 00:03:59,940
we can't overlook the importance

118
00:03:59,940 --> 00:04:02,280
of conducting a supply chain analysis.

119
00:04:02,280 --> 00:04:04,860
A supply chain analysis is going to be used to dive deep

120
00:04:04,860 --> 00:04:06,690
into a vendor's entire supply chain

121
00:04:06,690 --> 00:04:09,810
and to assess the security and reliability of each link.

122
00:04:09,810 --> 00:04:11,040
It is an acknowledgement of the fact

123
00:04:11,040 --> 00:04:13,770
that the vendor's security is not just about their practices

124
00:04:13,770 --> 00:04:17,070
but also encompasses their entire supply chain's integrity.

125
00:04:17,070 --> 00:04:19,800
Now, for example, a hardware vendor might source parts

126
00:04:19,800 --> 00:04:21,630
from various global locations.

127
00:04:21,630 --> 00:04:24,330
A thorough supply chain analysis will then scrutinize each

128
00:04:24,330 --> 00:04:26,610
of these source locations to ensure there's no risk

129
00:04:26,610 --> 00:04:29,130
of counterfeit parts or tampered products entering

130
00:04:29,130 --> 00:04:30,330
into your supply chain.

131
00:04:30,330 --> 00:04:32,670
So remember, in today's interconnected businesses

132
00:04:32,670 --> 00:04:33,900
and global supply chains,

133
00:04:33,900 --> 00:04:36,120
the security and reliability of our vendors

134
00:04:36,120 --> 00:04:38,580
will directly impact our organization's own wellbeing

135
00:04:38,580 --> 00:04:39,600
and security.

136
00:04:39,600 --> 00:04:41,550
While trusting our partners is essential,

137
00:04:41,550 --> 00:04:42,960
actively ensuring their adherence

138
00:04:42,960 --> 00:04:45,690
to top-notch standards is also equally as important,

139
00:04:45,690 --> 00:04:48,240
as we need to ensure that we conduct a vendor assessment

140
00:04:48,240 --> 00:04:50,400
a contract review, a penetration test,

141
00:04:50,400 --> 00:04:53,130
and other internal or external audits to validate

142
00:04:53,130 --> 00:04:55,530
that our suppliers and vendors are remaining in compliance

143
00:04:55,530 --> 00:04:57,390
with the security requirements that are contained

144
00:04:57,390 --> 00:04:58,923
within our service contracts.

