Third-Party Management

Third-party management is the governance of the security risks that arise when an organization relies on vendors, suppliers, and service providers. Modern operations depend on external parties for software, infrastructure, and services, and each relationship can extend the organization's attack surface. This discipline aims to understand, reduce, and monitor that exposure across the full supplier lifecycle.

As part of operational governance, third-party management runs day to day because supplier relationships are continuous, not one-time events. It connects risk assessment, procurement, legal, and security operations so that external dependencies are evaluated before they are relied upon and watched for as long as they persist.

This area matters because a weakness in a supplier can become a weakness in the organization, regardless of how strong internal controls are. Incidents originating in the supply chain can affect many organizations at once, and responsibility for protecting data often cannot be outsourced even when the processing is.

The work includes assessing vendors before engagement, setting security expectations in contracts, such as requirements for safeguards, notification, and audit rights, and monitoring suppliers over time rather than only at onboarding. Risk is typically prioritized by how critical a supplier is and how sensitive the data or access involved, so effort is focused where exposure is greatest.

References#

  • NIST SP 800-161, Cybersecurity Supply Chain Risk Management Practices.
  • ISO/IEC 27036, Information security for supplier relationships.

Cookie Consent

We use cookies to enhance your experience. Learn more