SlideShare ist ein Scribd-Unternehmen logo
1 von 19
Implementing an
Effective Third Party
Risk Management
Program
Who am I? Jerod Brennen
InfoSec Geek
Security Architect, GBQ Partners
Alphabet Soup: CISSP, GWAPT, GWEB
@slandail
https://slandail.net/
https://gbq.com/
2
One Step
at a Time
▫ Securing Executive Buy-In
▫ Identifying Your Third Parties
▫ Prioritizing Your Assessments
▫ Conducting Initial Assessments
▫ Ongoing Management
▫ Automation
▫ Further Reading
3
$39.4
million
4
▫“According to the 2013
Trustwave Global
Security Report on 450
global data breach
investigations, 63%
were linked to a third-
party component of IT
system administration.”
Target Isn’t
Alone
5
▫- From
http://www.computer
weekly.com/news/224
0178104/Bad-
outsourcing-decisions-
cause-63-of-data-
breaches
Verizon DBIR
6
Who’s In Scope?
7
Identifying Your
Third Parties
▫ Talk to Accounts Payable
▫ Survey your end users
▫ Review your outbound Internet
traffic logs
8
Prioritizing Your Assessments
9
Image from http://www.isaca.org/Journal/archives/2006/Volume-5/Pages/JOnline-
Understanding-Data-Classification-Based-on-Business-and-Security-Requirements1.aspx
Think Like an
End User
Confidentiality Integrity Availability
10
Identifying Your
Third Parties
▫ Document your assessment
phases
▫ Document your question set
▫ Track assessments like
engagements/projects
11
Are You
Asking Me, or
Telling Me?
Shared
Assessments
https://sharedasses
sments.org/
Cloud Security
Alliance Cloud
Controls Matrix
https://cloudsecurit
yalliance.org/
SANS CIS Critical
Security Controls
https://www.sans.or
g/critical-security-
controls
12
NIST 800-53 rev4
http://nvlpubs.nist.g
ov/nistpubs/Specia
lPublications/NIST.S
P.800-53r4.pdf
ISO 27002:2013
http://www.iso.org/
iso/catalogue_detail
?csnumber=54533
Common Sense
Security Framework
(CSSF)
http://www.commo
nsenseframework.or
g/
You Do This
▫ Security Risk
Assessment
Learn to Love
the Attestation
You Ask For These
▫ Security Controls
Assessment
▫ Technical
Vulnerability
Assessment
▫ Privacy Assessment
▫ Compliance
Assessment
▫ Penetration Test
▫ IT Audits
13
Don’t Fear the
OSINT
▫ Google Finance
▫ LinkedIn
▫ Chronology of Data Breaches
▫ PasteBin
▫ Qualys SSL Server Test
▫ Mozilla Observatory
▫ PunkSPIDER
▫ Shodan
▫ Censys14
Ongoing
Assessments
▫ Frequency?
▫ What’s Changed?
▫ Automate all the things!
15
Speaking of
Automation
▫ Prevalent
▫ Skyhigh Networks
▫ BitSight
16
Getting Ahead
of the Curve
▫ Lock down your internal data
classification procedures.
▫ Identify a process-oriented employee
who can own/manage this process.
▫ Start talking to IT Vendor Risk
Management vendors.
▫ Document a question set that’s relevant
to your organization (framework).
▫ Add a security/risk assessment
requirement to your purchasing
process/form.17
Further Reading ▫ Missed Alarms and 40 Million Stolen Credit Card
Numbers: How Target Blew It
▫ http://www.bloomberg.com/bw/articles/2014-
03-13/target-missed-alarms-in-epic-hack-of-
credit-card-data
▫ Verizon 2015 Data Breach Investigations Report
▫ http://www.verizonenterprise.com/DBIR/2015/
▫ NAVEX Global Definitive Guide to Third Party Risk
Management
▫ http://www.navexglobal.com/en-
us/resources/ebooks/definitive-guide-to-third-
party-risk18
19
THANKS! Any questions?
You can find me at
▫ @slandail
▫ jbrennen@gbq.com

Weitere ähnliche Inhalte

Mehr von Jerod Brennen

Common Sense Security Framework
Common Sense Security FrameworkCommon Sense Security Framework
Common Sense Security FrameworkJerod Brennen
 
Please, Please, PLEASE Defend Your Mobile Apps!
Please, Please, PLEASE Defend Your Mobile Apps!Please, Please, PLEASE Defend Your Mobile Apps!
Please, Please, PLEASE Defend Your Mobile Apps!Jerod Brennen
 
Integrating security into the application development process
Integrating security into the application development processIntegrating security into the application development process
Integrating security into the application development processJerod Brennen
 
Bridging the Social Media Implementation/Audit Gap
Bridging the Social Media Implementation/Audit GapBridging the Social Media Implementation/Audit Gap
Bridging the Social Media Implementation/Audit GapJerod Brennen
 
Attacking and Defending Mobile Applications
Attacking and Defending Mobile ApplicationsAttacking and Defending Mobile Applications
Attacking and Defending Mobile ApplicationsJerod Brennen
 
Identity and Access Management 101
Identity and Access Management 101Identity and Access Management 101
Identity and Access Management 101Jerod Brennen
 
DDoS Attack Preparation and Mitigation
DDoS Attack Preparation and MitigationDDoS Attack Preparation and Mitigation
DDoS Attack Preparation and MitigationJerod Brennen
 
Information Security Management 101
Information Security Management 101Information Security Management 101
Information Security Management 101Jerod Brennen
 

Mehr von Jerod Brennen (8)

Common Sense Security Framework
Common Sense Security FrameworkCommon Sense Security Framework
Common Sense Security Framework
 
Please, Please, PLEASE Defend Your Mobile Apps!
Please, Please, PLEASE Defend Your Mobile Apps!Please, Please, PLEASE Defend Your Mobile Apps!
Please, Please, PLEASE Defend Your Mobile Apps!
 
Integrating security into the application development process
Integrating security into the application development processIntegrating security into the application development process
Integrating security into the application development process
 
Bridging the Social Media Implementation/Audit Gap
Bridging the Social Media Implementation/Audit GapBridging the Social Media Implementation/Audit Gap
Bridging the Social Media Implementation/Audit Gap
 
Attacking and Defending Mobile Applications
Attacking and Defending Mobile ApplicationsAttacking and Defending Mobile Applications
Attacking and Defending Mobile Applications
 
Identity and Access Management 101
Identity and Access Management 101Identity and Access Management 101
Identity and Access Management 101
 
DDoS Attack Preparation and Mitigation
DDoS Attack Preparation and MitigationDDoS Attack Preparation and Mitigation
DDoS Attack Preparation and Mitigation
 
Information Security Management 101
Information Security Management 101Information Security Management 101
Information Security Management 101
 

Kürzlich hochgeladen

FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756dollysharma2066
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptxnandhinijagan9867
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...lizamodels9
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...amitlee9823
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noidadlhescort
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1kcpayne
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...rajveerescorts2022
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 

Kürzlich hochgeladen (20)

FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 

Implementing an Effective Third Party Risk Management Program

  • 1. Implementing an Effective Third Party Risk Management Program
  • 2. Who am I? Jerod Brennen InfoSec Geek Security Architect, GBQ Partners Alphabet Soup: CISSP, GWAPT, GWEB @slandail https://slandail.net/ https://gbq.com/ 2
  • 3. One Step at a Time ▫ Securing Executive Buy-In ▫ Identifying Your Third Parties ▫ Prioritizing Your Assessments ▫ Conducting Initial Assessments ▫ Ongoing Management ▫ Automation ▫ Further Reading 3
  • 5. ▫“According to the 2013 Trustwave Global Security Report on 450 global data breach investigations, 63% were linked to a third- party component of IT system administration.” Target Isn’t Alone 5 ▫- From http://www.computer weekly.com/news/224 0178104/Bad- outsourcing-decisions- cause-63-of-data- breaches
  • 8. Identifying Your Third Parties ▫ Talk to Accounts Payable ▫ Survey your end users ▫ Review your outbound Internet traffic logs 8
  • 9. Prioritizing Your Assessments 9 Image from http://www.isaca.org/Journal/archives/2006/Volume-5/Pages/JOnline- Understanding-Data-Classification-Based-on-Business-and-Security-Requirements1.aspx
  • 10. Think Like an End User Confidentiality Integrity Availability 10
  • 11. Identifying Your Third Parties ▫ Document your assessment phases ▫ Document your question set ▫ Track assessments like engagements/projects 11
  • 12. Are You Asking Me, or Telling Me? Shared Assessments https://sharedasses sments.org/ Cloud Security Alliance Cloud Controls Matrix https://cloudsecurit yalliance.org/ SANS CIS Critical Security Controls https://www.sans.or g/critical-security- controls 12 NIST 800-53 rev4 http://nvlpubs.nist.g ov/nistpubs/Specia lPublications/NIST.S P.800-53r4.pdf ISO 27002:2013 http://www.iso.org/ iso/catalogue_detail ?csnumber=54533 Common Sense Security Framework (CSSF) http://www.commo nsenseframework.or g/
  • 13. You Do This ▫ Security Risk Assessment Learn to Love the Attestation You Ask For These ▫ Security Controls Assessment ▫ Technical Vulnerability Assessment ▫ Privacy Assessment ▫ Compliance Assessment ▫ Penetration Test ▫ IT Audits 13
  • 14. Don’t Fear the OSINT ▫ Google Finance ▫ LinkedIn ▫ Chronology of Data Breaches ▫ PasteBin ▫ Qualys SSL Server Test ▫ Mozilla Observatory ▫ PunkSPIDER ▫ Shodan ▫ Censys14
  • 15. Ongoing Assessments ▫ Frequency? ▫ What’s Changed? ▫ Automate all the things! 15
  • 16. Speaking of Automation ▫ Prevalent ▫ Skyhigh Networks ▫ BitSight 16
  • 17. Getting Ahead of the Curve ▫ Lock down your internal data classification procedures. ▫ Identify a process-oriented employee who can own/manage this process. ▫ Start talking to IT Vendor Risk Management vendors. ▫ Document a question set that’s relevant to your organization (framework). ▫ Add a security/risk assessment requirement to your purchasing process/form.17
  • 18. Further Reading ▫ Missed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It ▫ http://www.bloomberg.com/bw/articles/2014- 03-13/target-missed-alarms-in-epic-hack-of- credit-card-data ▫ Verizon 2015 Data Breach Investigations Report ▫ http://www.verizonenterprise.com/DBIR/2015/ ▫ NAVEX Global Definitive Guide to Third Party Risk Management ▫ http://www.navexglobal.com/en- us/resources/ebooks/definitive-guide-to-third- party-risk18
  • 19. 19 THANKS! Any questions? You can find me at ▫ @slandail ▫ jbrennen@gbq.com

Hinweis der Redaktion

  1. Talk to Accounts Payable SOMEONE’S getting paid Survey your end users “Which websites do you login to in order to do your job?” Review your outbound Internet traffic logs Web traffic (cloud service logins) SFTP/SSH traffic (commonly used for secure file transfers)
  2. Document Your Assessment Phases Engagement Phase – Define scope, define rules of engagement, exchange information Assessment Phase – Review information, identify threats, estimate risk Review Phase – Document findings, make recommendations, present report for approval Document Your Question Set How much is too much? What is your internal security/compliance framework? NIST (FISMA), ISO 27000 Series, PCI, HIPAA Track assessments like engagements/projects Task owners, due dates, milestones
  3. Frequency? Low Priority = Annually Medium Priority = Semi-Annually High Priority = Quarterly What’s changed? Business model Operating environment/locations Technology stack Vendor’s partners AUTOMATE ALL THE THINGS!!!
  4. Consider deployed technologies GRC Solution (Governance, Risk, and Compliance) Service Desk Solution IT Vendor (& Cloud) Risk Management Prevalent - http://www.prevalent.net/ Skyhigh Networks - https://www.skyhighnetworks.com/ BitSight - https://www.bitsighttech.com/