Expert Advice Community

Guest

Security risks dealing with suppliers

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Security risks dealing with suppliers

This may sound a little odd a question at this stage of the implementation, but How do we get to what is a security risk in the first place when dealing with suppliers etc, how can this be done specifically?
0 0

Assign topic to the user

ISO 27001 SUPPLIER SECURITY POLICY

Define how suppliers and partners need to keep your information safe.

ISO 27001 SUPPLIER SECURITY POLICY

Define how suppliers and partners need to keep your information safe.

Guest
AntonioS Jan 12, 2016

Presently, our risk assessment is assessing risks that refer to assets vs. CIA.
Other risks that are brought to our attention are those from security incidents /breaches etc, so this is the easy part.
 

Answer:

If you outsource part of your processes or allow a third party to access your information, you should assess the risks to confidentiality, integrity and availability of your information. For example, during the risk assessment you may realize that some of your information might be exposed to the public and create huge damage, or that some information may be permanently lost. Based on the results of risk assessment, you can decide whether the next steps in this process are necessary or not – for example, you may not need to perform a background check or insert security clauses for your cafeteria supplier, but you probably w ill need to do it for your software developer. For more information about it, you can read this article “6-step process for handling supplier” : https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016