enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Bank OZK [NASDAQ: OZK]

Information Security and Your Third Party

Jeff Evans, Chief Information Security Officer, Bank OZK [NASDAQ: OZK]

Within the information security industry there is one thing that all information security professionals can agree on. Your organization’s third parties increase your information security risk. When discussing third party information security risk, we cannot ignore the access and privileges these third parties have within your environment. The following analogy is one I like to use to describe this complicated but often necessary relationship.

Third Parties are like our neighbors. There is a relationship; now it may be light as only saying hello as you see each other, or it could be as close as allowing your neighbor to have a spare key to your home in case of emergencies. Utilizing this analogy, you can see where your “neighbor” may have minimal access and privileges, or complete access to your “home.” Properly identifying and assessing the risk of this relationship should prevent uncontrolled access and privileges, right? But what if the relationship changes, such as your dependency of this “neighbor.” What then?

Well, your organization needs to re-assess the relationship with the third party just like you would reassess your neighbor. First, an organization needs to understand this relationship. This starts with communication. Your organization needs to know what this third party will be providing in this relationship and what type of access and privileges are warranted. Within the communication, identifying access to protected data sets such as personable identifiable information (PII), or personable health information (PHI) is a perfect starting point. After all, information security is ultimately the mitigation of data risk. Once an organization has a good understanding of third party interactions with data sets; access and privilege controls to those data sets can be implemented.

Practicing sound information security principles such as ‘least privilege’ and ‘need-to-know’ can prevent unauthorized access and limit the data risk. However, an organization may need to allow a third party access to PII or PHI. That does not mean all data within the organization, however. Segmenting these data sets or only permitting access to specific information is key to controlling the data risk. Controlling the data risk ultimately controls the risk between your organization and the third party relationship.

“An organization can be better off in truly dealing with third party risk and ultimately what controls need to be in place”

Let us circle back to the analogy previously mentioned. Now, I have a neighbor that I have become close with and through this relationship I have determined this neighbor to be trustworthy and responsible (assessed). I provided my neighbor a key (access) and permission (privilege) to collect my mail (PII/PHI) and bring it into my home (organization) when I am away on vacation. As you can tell, the access and permission to protected data is allowed but with one clear objective. To bring my mail into my home, nothing more and nothing less. This is the relationship I have with my neighbor like the relationship an organization needs to have with a third party.

Utilizing this train of thought, an organization can be better off in truly dealing with third party risk and ultimately what controls need to be in place. This is not a fix all for third party relationships, but it should provide a better understanding of the process required to implement controls to mitigate risk. We all know relationships are complicated, but communication is key. And through this communication, with the right train of thought, your organization’s (you) and third party’s (neighbor) relationship can be safe, controlled, and effective.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.