enterprisesecuritymag

| | DECEMBER 2020ENTERPRISE SECURITY8IN MY OPINIONMost of the stress in our lives comes from trying to control things we don't have control over. As individuals, there are a range of tools available to help us cope with change and deal with things that are out of our control. As organizations, however, we need to understand and find ways to manage things that are technically outside of our direct control. We live in a highly-connected world where collaboration and partnerships are an essential part of the speed and way we work today. When we engage in these types of business relationships though, we need to share data, information and sometimes even system access with people and businesses outside of our organization. More and more, our ability to do this in a short time frame is becoming a business differentiator, but of course, this brings with it several new dimensions of business risk. In this environment, third-party risk management is becoming a huge area of focus within cybersecurity. Regulatory frameworks, both locally and globally, are also catching up and insisting that third-party risk be included in control reviews and statements of compliance. So, with the pressure of speed to market and the huge potential attack surface that is opened when we share data and systems, how can financial services organizations best manage their third-party risks?Much like individual stress, the best way to start is to control the risks we can, really effectively, and to be clear about those we can't. This will allow the business to make an informed decision about whether to support a third-party agreement. So, although it may sound somewhat counter-intuitive, the best place to start when it comes to assessing third-party risk exposure is with yourself. You should consider questions such as: do you have a comprehensive list of all third-parties that take or use your organizations data? Do you understand which systems have third-party access? Do you have a good grasp of shadow IT? Once you are confident, you have an accurate map of where all your data is and who has access to or uses it, the real work can then begin.Approaches to third-party risk managementMost third-party risk is managed by sending out questionnaires asking the third-parties to identify Managing Third-Party RiskBy Jacqui Kernot, Partner, Ernst & Young Jacqui Kernot
< Page 7 | Page 9 >