1
00:00:06,480 --> 00:00:08,070
- Welcome to lesson 25,

2
00:00:08,070 --> 00:00:09,840
explain the process associated

3
00:00:09,840 --> 00:00:13,170
with third party risk
assessment and management.

4
00:00:13,170 --> 00:00:15,270
Now, in this lesson, 25.1

5
00:00:15,270 --> 00:00:16,103
we're gonna focus

6
00:00:16,103 --> 00:00:18,660
in on third party risk management.

7
00:00:18,660 --> 00:00:19,920
Third party risk management

8
00:00:19,920 --> 00:00:21,570
is a composite activities

9
00:00:21,570 --> 00:00:23,340
that we use to research

10
00:00:23,340 --> 00:00:25,380
and source our third parties,

11
00:00:25,380 --> 00:00:27,780
conduct due diligence investigations,

12
00:00:27,780 --> 00:00:31,140
negotiate our contracts,
manage relationships,

13
00:00:31,140 --> 00:00:32,880
evaluate performance,

14
00:00:32,880 --> 00:00:35,100
and make our payments.

15
00:00:35,100 --> 00:00:38,310
Now, third parties include
vendors, contractors,

16
00:00:38,310 --> 00:00:41,160
business partners, and service providers.

17
00:00:41,160 --> 00:00:44,250
Our fourth parties are
sub-service organizations

18
00:00:44,250 --> 00:00:45,210
of third parties.

19
00:00:45,210 --> 00:00:46,110
Now, I know you know that

20
00:00:46,110 --> 00:00:48,063
because we've already talked about it.

21
00:00:49,710 --> 00:00:50,880
Third party oversight

22
00:00:50,880 --> 00:00:52,890
is the implementation of strategies

23
00:00:52,890 --> 00:00:56,580
to manage uncertainty,
identify vulnerabilities

24
00:00:56,580 --> 00:01:00,540
and ensure compliance and continuity.

25
00:01:00,540 --> 00:01:01,380
There's a whole range

26
00:01:01,380 --> 00:01:03,780
of third party oversight activities

27
00:01:03,780 --> 00:01:05,820
including conducting due diligence

28
00:01:05,820 --> 00:01:08,970
investigations related to the
service provider selection

29
00:01:08,970 --> 00:01:11,280
and subsequent business activities,

30
00:01:11,280 --> 00:01:14,310
requiring NDAs or
non-disclosure agreements,

31
00:01:14,310 --> 00:01:16,920
codifying our service relationships,

32
00:01:16,920 --> 00:01:19,860
coordinating our incident
response protocols

33
00:01:19,860 --> 00:01:21,840
and contractual notification

34
00:01:21,840 --> 00:01:24,000
and then monitoring the service provider

35
00:01:24,000 --> 00:01:26,313
through appropriate audits and testing.

36
00:01:28,080 --> 00:01:29,760
So let's talk about due diligence, right?

37
00:01:29,760 --> 00:01:32,910
Due diligence is the act
of investigating, right,

38
00:01:32,910 --> 00:01:34,920
a third party before we're going

39
00:01:34,920 --> 00:01:36,720
to enter into a business contract

40
00:01:36,720 --> 00:01:40,650
and then during the subsequent
business activities.

41
00:01:40,650 --> 00:01:42,000
And certainly we're gonna do it again

42
00:01:42,000 --> 00:01:43,920
before we renew a contract.

43
00:01:43,920 --> 00:01:45,450
So what are some of the
things that we'd look

44
00:01:45,450 --> 00:01:47,790
at from an information
security perspective

45
00:01:47,790 --> 00:01:49,410
in terms of due diligence?

46
00:01:49,410 --> 00:01:51,210
Controls, compliance,

47
00:01:51,210 --> 00:01:53,370
vulnerability management, end of life

48
00:01:53,370 --> 00:01:55,950
end of support assessment, the right

49
00:01:55,950 --> 00:01:57,895
to audit, incident management,

50
00:01:57,895 --> 00:02:00,033
and business continuity.

51
00:02:01,290 --> 00:02:03,720
So we're looking at the vendor's ability

52
00:02:03,720 --> 00:02:05,760
to implement required security

53
00:02:05,760 --> 00:02:08,550
and privacy controls,
but not just for them.

54
00:02:08,550 --> 00:02:11,430
We also wanna be inclusive
of fourth parties.

55
00:02:11,430 --> 00:02:13,413
These are the controls we're requiring.

56
00:02:14,280 --> 00:02:16,680
Compliance is the third
party's understanding

57
00:02:16,680 --> 00:02:19,230
of and their ability to comply

58
00:02:19,230 --> 00:02:21,183
with regulatory requirements.

59
00:02:22,230 --> 00:02:24,000
Vulnerability management is assuring

60
00:02:24,000 --> 00:02:27,690
that they will disclose
in their vulnerabilities

61
00:02:27,690 --> 00:02:29,640
and understanding what is the frequency

62
00:02:29,640 --> 00:02:31,023
of their patch releases.

63
00:02:32,490 --> 00:02:34,050
For end of life and end of support,

64
00:02:34,050 --> 00:02:35,580
we wanna make sure that we understand

65
00:02:35,580 --> 00:02:36,450
their end of life

66
00:02:36,450 --> 00:02:38,520
and end of support cycle,

67
00:02:38,520 --> 00:02:40,290
as well as the notification

68
00:02:40,290 --> 00:02:42,033
and how they offer their support.

69
00:02:43,170 --> 00:02:45,630
For assessment, it's
always great to have proof

70
00:02:45,630 --> 00:02:47,550
of independent security testing

71
00:02:47,550 --> 00:02:49,020
and many third parties will say, "Oh

72
00:02:49,020 --> 00:02:50,160
I'll show you our own testing."

73
00:02:50,160 --> 00:02:51,000
It's like, no, no, no.

74
00:02:51,000 --> 00:02:52,503
I want independent testing.

75
00:02:54,030 --> 00:02:56,370
The right to audit is
an agreement to allow

76
00:02:56,370 --> 00:02:59,670
either independent audits,
so we bring somebody

77
00:02:59,670 --> 00:03:01,530
in to audit a third party

78
00:03:01,530 --> 00:03:04,950
or to provide equivalent audit material.

79
00:03:04,950 --> 00:03:06,900
And we'll be talking
about that when we talk

80
00:03:06,900 --> 00:03:09,123
about SSAE18 reports.

81
00:03:10,380 --> 00:03:12,660
Incident management is their detection

82
00:03:12,660 --> 00:03:14,370
and response capabilities,

83
00:03:14,370 --> 00:03:15,570
as well as understanding

84
00:03:15,570 --> 00:03:18,000
their security breach protocols.

85
00:03:18,000 --> 00:03:19,410
And then business continuity

86
00:03:19,410 --> 00:03:20,760
will be their ability

87
00:03:20,760 --> 00:03:22,950
to continue to provide service

88
00:03:22,950 --> 00:03:25,740
and to operate in adverse conditions.

89
00:03:25,740 --> 00:03:26,573
So these are all

90
00:03:26,573 --> 00:03:27,510
of the things that we wanna

91
00:03:27,510 --> 00:03:29,777
look at for the third party.

92
00:03:29,777 --> 00:03:31,923
how they do it, what they can do.

93
00:03:33,690 --> 00:03:34,650
Let's dig a little deeper

94
00:03:34,650 --> 00:03:36,180
into right to audit.

95
00:03:36,180 --> 00:03:37,770
A right to audit contract

96
00:03:37,770 --> 00:03:40,440
provision clause grants
the contract holder

97
00:03:40,440 --> 00:03:43,410
the right to conduct or oversee an audit

98
00:03:43,410 --> 00:03:47,280
of the service provider's
facilities and practices.

99
00:03:47,280 --> 00:03:50,010
Now, this provision is
often limited to annually,

100
00:03:50,010 --> 00:03:51,180
unless there's been a security

101
00:03:51,180 --> 00:03:52,800
breach or a complaint related

102
00:03:52,800 --> 00:03:54,480
to the service provider's privacy

103
00:03:54,480 --> 00:03:56,310
or security practices.

104
00:03:56,310 --> 00:03:58,350
An alternative is requiring

105
00:03:58,350 --> 00:04:01,350
the service provider to
have independent audits

106
00:04:01,350 --> 00:04:04,320
of its own compliance
with industry standards.

107
00:04:04,320 --> 00:04:07,470
For example, doing an SSAE18 audit report,

108
00:04:07,470 --> 00:04:09,030
having that being completed

109
00:04:09,030 --> 00:04:11,400
and the results being provided.

110
00:04:11,400 --> 00:04:12,480
And once again, we're gonna look

111
00:04:12,480 --> 00:04:15,513
at the SSAE18 in a future lesson.

112
00:04:17,430 --> 00:04:19,620
Now, there are some third party agreements

113
00:04:19,620 --> 00:04:20,940
that we're going to wanna have.

114
00:04:20,940 --> 00:04:23,280
And so let's look at the
first type of agreements

115
00:04:23,280 --> 00:04:25,680
which are referred to
as strategic agreements.

116
00:04:25,680 --> 00:04:30,680
An NDA, an MOU, an MOA and a BPA.

117
00:04:31,350 --> 00:04:33,900
An NDA stands for
Non-Disclosure Agreement.

118
00:04:33,900 --> 00:04:36,240
And that agreement establishes ownership

119
00:04:36,240 --> 00:04:39,420
and protects information
from unauthorized disclosure

120
00:04:39,420 --> 00:04:42,870
and use both during and post relationship.

121
00:04:42,870 --> 00:04:45,060
And we talked about an
NDA when we were talking

122
00:04:45,060 --> 00:04:47,040
about agreements that we
might have with employees,

123
00:04:47,040 --> 00:04:48,270
consultants or contractors,

124
00:04:48,270 --> 00:04:50,220
people inside our organization.

125
00:04:50,220 --> 00:04:52,170
That point we talked about it as an NDA

126
00:04:52,170 --> 00:04:55,023
and also refer to it as a
confidentiality agreement.

127
00:04:56,310 --> 00:04:59,580
An MOU is a memorandum of understanding

128
00:04:59,580 --> 00:05:01,320
that's a key word, understanding.

129
00:05:01,320 --> 00:05:04,050
It's a non-binding document that really

130
00:05:04,050 --> 00:05:06,900
outlines the intentions and the areas

131
00:05:06,900 --> 00:05:10,083
of future cooperation between the parties.

132
00:05:10,980 --> 00:05:13,950
A memorandum of agreement is binding.

133
00:05:13,950 --> 00:05:16,470
It's a legally enforceable document,

134
00:05:16,470 --> 00:05:18,060
that establishes a contractual

135
00:05:18,060 --> 00:05:21,150
relationship between the parties.

136
00:05:21,150 --> 00:05:22,890
And lastly, a BPA.

137
00:05:22,890 --> 00:05:24,360
That's a business partner agreement.

138
00:05:24,360 --> 00:05:27,000
It's really a fancy way
of saying a contract,

139
00:05:27,000 --> 00:05:29,850
but it's a comprehensive legal document

140
00:05:29,850 --> 00:05:31,320
that outlines the terms

141
00:05:31,320 --> 00:05:33,540
and conditions of the relationship

142
00:05:33,540 --> 00:05:37,050
between two or more
businesses or entities.

143
00:05:37,050 --> 00:05:40,800
So NDAs, MOUs, MOAs, and BPAs.

144
00:05:40,800 --> 00:05:42,390
And they're considered strategic

145
00:05:42,390 --> 00:05:43,440
because they're really high level

146
00:05:43,440 --> 00:05:44,940
documents that are setting

147
00:05:44,940 --> 00:05:47,613
up the parameters of a relationship.

148
00:05:49,230 --> 00:05:50,460
Then we have some tactical

149
00:05:50,460 --> 00:05:51,540
third party agreements.

150
00:05:51,540 --> 00:05:53,220
These are more nuts and bolts.

151
00:05:53,220 --> 00:05:58,220
We have SLA, MSA, SOW and WO.

152
00:05:58,740 --> 00:06:02,157
SLA stands for service level agreement.

153
00:06:02,157 --> 00:06:04,770
And MSA is a master services agreement.

154
00:06:04,770 --> 00:06:07,080
And SOW is a statement of work,

155
00:06:07,080 --> 00:06:09,600
and a WO is a work order.

156
00:06:09,600 --> 00:06:11,880
An SLA is a service level agreement

157
00:06:11,880 --> 00:06:13,260
that codifies service

158
00:06:13,260 --> 00:06:14,880
and support requirements

159
00:06:14,880 --> 00:06:16,860
and may include incentives

160
00:06:16,860 --> 00:06:19,110
for great work and or penalties

161
00:06:19,110 --> 00:06:20,703
for not so great work.

162
00:06:21,840 --> 00:06:24,720
An MSA is a master services agreement

163
00:06:24,720 --> 00:06:26,610
and it outlines sort of general

164
00:06:26,610 --> 00:06:29,910
terms and conditions and
it serves as a framework

165
00:06:29,910 --> 00:06:33,513
for future agreements or
projects between the parties.

166
00:06:35,220 --> 00:06:36,750
An SOW is a statement

167
00:06:36,750 --> 00:06:38,850
of work that defines tasks,

168
00:06:38,850 --> 00:06:43,050
deliverables, timelines and
performance expectations,

169
00:06:43,050 --> 00:06:46,110
for a particular project or an engagement

170
00:06:46,110 --> 00:06:49,140
between the client and
the service provider.

171
00:06:49,140 --> 00:06:52,740
So the MSA is kind of the
umbrella of your SOWs.

172
00:06:52,740 --> 00:06:55,533
And then for each project
you'll have an SOW.

173
00:06:56,640 --> 00:06:59,250
And then work order is just transactional

174
00:06:59,250 --> 00:07:00,810
and it's used for individual

175
00:07:00,810 --> 00:07:02,100
service requests,

176
00:07:02,100 --> 00:07:03,483
often within the context

177
00:07:03,483 --> 00:07:06,600
of the ongoing business relationship.

178
00:07:06,600 --> 00:07:11,223
So SLAs, MSAs, SOWs and WOs.

179
00:07:12,660 --> 00:07:15,810
And that my friends brings us
to a three second challenge.

180
00:07:15,810 --> 00:07:17,730
Five challenge questions,
three seconds each.

181
00:07:17,730 --> 00:07:18,563
Let's do it.

182
00:07:19,650 --> 00:07:21,630
An agreement that specifies the service

183
00:07:21,630 --> 00:07:23,340
and support commitment.

184
00:07:23,340 --> 00:07:25,860
One, two, three.

185
00:07:25,860 --> 00:07:28,890
That's an SLA or service level agreement.

186
00:07:28,890 --> 00:07:30,990
Number two, contractual clause

187
00:07:30,990 --> 00:07:34,023
that agrees to allow an
audit to be conducted.

188
00:07:35,130 --> 00:07:36,723
One, two, three.

189
00:07:37,740 --> 00:07:39,543
That is right to audit clause.

190
00:07:40,710 --> 00:07:41,583
Number three.

191
00:07:42,600 --> 00:07:44,520
An agreement that protects information

192
00:07:44,520 --> 00:07:46,450
from unauthorized disclosure during

193
00:07:46,450 --> 00:07:48,303
and post relationship.

194
00:07:49,290 --> 00:07:50,733
One, two, three.

195
00:07:51,750 --> 00:07:54,450
That's gonna be an NDA, a
non-disclosure agreement

196
00:07:54,450 --> 00:07:56,943
also referred to as a
confidentiality agreement.

197
00:07:58,290 --> 00:07:59,190
Number four.

198
00:07:59,190 --> 00:08:01,090
An investigation of a business

199
00:08:01,090 --> 00:08:04,097
or person before entering into a contract

200
00:08:04,097 --> 00:08:06,483
and during the lifetime
of the relationship.

201
00:08:07,800 --> 00:08:09,573
One, two, three.

202
00:08:10,530 --> 00:08:12,660
That's gonna be doing due diligence.

203
00:08:12,660 --> 00:08:14,760
And lastly, number five.

204
00:08:14,760 --> 00:08:18,063
Used to document individual
service requests.

205
00:08:19,260 --> 00:08:20,493
One, two, three.

206
00:08:21,540 --> 00:08:23,253
That's gonna be a work order.

207
00:08:24,960 --> 00:08:27,000
That brings us to a security-in-action.

208
00:08:27,000 --> 00:08:29,580
And this one's about due diligence.

209
00:08:29,580 --> 00:08:31,350
Now your organization has plans

210
00:08:31,350 --> 00:08:33,240
to outsource the hosting

211
00:08:33,240 --> 00:08:35,100
of its online store.

212
00:08:35,100 --> 00:08:36,343
Now you've been asked to conduct

213
00:08:36,343 --> 00:08:38,550
the cybersecurity component

214
00:08:38,550 --> 00:08:41,160
of the due diligence investigation.

215
00:08:41,160 --> 00:08:44,070
What areas would you focus on?

216
00:08:44,070 --> 00:08:46,230
Okay, so just a quick recap.

217
00:08:46,230 --> 00:08:48,120
We're gonna outsource the hosting

218
00:08:48,120 --> 00:08:49,890
of our online store.

219
00:08:49,890 --> 00:08:50,940
So we're looking at a number

220
00:08:50,940 --> 00:08:52,680
of different vendors I assume

221
00:08:52,680 --> 00:08:54,540
and we're gonna be doing
some due diligence.

222
00:08:54,540 --> 00:08:56,010
And you've been been asked

223
00:08:56,010 --> 00:08:58,080
to conduct the cybersecurity

224
00:08:58,080 --> 00:08:59,970
component of the overall

225
00:08:59,970 --> 00:09:02,100
due diligence investigation.

226
00:09:02,100 --> 00:09:03,540
So my question for you is,

227
00:09:03,540 --> 00:09:05,040
what are you gonna focus on?

228
00:09:05,040 --> 00:09:07,261
Go ahead and put me on pause

229
00:09:07,261 --> 00:09:09,693
and think about what
your focus is gonna be.

230
00:09:13,770 --> 00:09:16,740
Well, it's critical that
the third party security

231
00:09:16,740 --> 00:09:19,230
posture is strategically aligned

232
00:09:19,230 --> 00:09:21,510
with the needs of the organization.

233
00:09:21,510 --> 00:09:23,910
So you need to know what
your requirements are,

234
00:09:23,910 --> 00:09:26,610
so that we can assess the third party.

235
00:09:26,610 --> 00:09:27,473
So areas to focus

236
00:09:27,473 --> 00:09:30,450
on are going to include
their controls environment.

237
00:09:30,450 --> 00:09:32,750
Again, what controls do
you want them to have?

238
00:09:33,600 --> 00:09:35,160
Compliance requirements,

239
00:09:35,160 --> 00:09:36,960
if there are any compliance requirements,

240
00:09:36,960 --> 00:09:39,360
do they understand those
compliance requirements?

241
00:09:39,360 --> 00:09:42,303
And can they honor those
compliance requirements?

242
00:09:43,380 --> 00:09:44,850
Do they do assessments?

243
00:09:44,850 --> 00:09:46,440
Not just their own assessments

244
00:09:46,440 --> 00:09:48,420
but do they have independent assessments?

245
00:09:48,420 --> 00:09:50,730
And are they willing to share the results

246
00:09:50,730 --> 00:09:52,200
of those assessments with you?

247
00:09:52,200 --> 00:09:54,363
And how often do they do them?

248
00:09:55,470 --> 00:09:56,640
Do you have the right to audit?

249
00:09:56,640 --> 00:09:57,783
Meaning the right to actually go

250
00:09:57,783 --> 00:10:00,660
and do an audit on a specific basis,

251
00:10:00,660 --> 00:10:01,890
like an annual basis

252
00:10:01,890 --> 00:10:04,080
or if there's a particular complaint

253
00:10:04,080 --> 00:10:05,580
or are they willing to provide

254
00:10:05,580 --> 00:10:09,573
to you a comprehensive
SSAE18 audit report?

255
00:10:11,370 --> 00:10:12,900
You wanna learn about their end

256
00:10:12,900 --> 00:10:15,363
of support and end of life policies.

257
00:10:16,440 --> 00:10:18,750
You wanna understand
what their vulnerability

258
00:10:18,750 --> 00:10:20,250
management program looks like

259
00:10:20,250 --> 00:10:22,500
and how often do they
disclose vulnerabilities?

260
00:10:22,500 --> 00:10:25,320
And do they have a good
proactive history of,

261
00:10:25,320 --> 00:10:27,453
you know doing responsible disclosure?

262
00:10:28,530 --> 00:10:31,173
And then how often do they
release their patches?

263
00:10:32,100 --> 00:10:34,380
And then how are they gonna
handle incident management

264
00:10:34,380 --> 00:10:36,030
and do their incident response

265
00:10:36,030 --> 00:10:39,480
and management protocols, do
they work with yours, right?

266
00:10:39,480 --> 00:10:40,743
Can they work together?

267
00:10:41,910 --> 00:10:43,980
And lastly, their business continuity.

268
00:10:43,980 --> 00:10:44,940
What is their ability

269
00:10:44,940 --> 00:10:46,890
to continue to provide service

270
00:10:46,890 --> 00:10:48,240
in the event of an outage

271
00:10:48,240 --> 00:10:51,150
or disruption of their organization?

272
00:10:51,150 --> 00:10:52,110
So those are all the things

273
00:10:52,110 --> 00:10:53,310
we're gonna look at for,

274
00:10:53,310 --> 00:10:55,380
at the service provider to make sure

275
00:10:55,380 --> 00:10:58,830
that they can provide the
adequate level of service

276
00:10:58,830 --> 00:11:01,770
and compliance and controls.

277
00:11:01,770 --> 00:11:03,240
Being able to do this,

278
00:11:03,240 --> 00:11:04,473
security-in-action.

279
00:11:05,640 --> 00:11:06,473
All right.

280
00:11:06,473 --> 00:11:08,130
There's your word cloud.

281
00:11:08,130 --> 00:11:09,510
Make sure that you really

282
00:11:09,510 --> 00:11:11,190
know all of these terms, right?

283
00:11:11,190 --> 00:11:12,990
Any one of them could
come up in your exam.

284
00:11:12,990 --> 00:11:14,070
So you wanna understand them

285
00:11:14,070 --> 00:11:15,600
and be confident in them.

286
00:11:15,600 --> 00:11:16,470
And then when you're ready,

287
00:11:16,470 --> 00:11:18,240
well, we only had one lesson

288
00:11:18,240 --> 00:11:20,400
in this lesson, so head on over

289
00:11:20,400 --> 00:11:21,873
to our five question quiz.
