DECEMBER 2020ENTERPRISE SECURITY| | 9where they might have processes or systems which may create a risk. The issue with this approach is that the questionnaires are often not based on a good understanding of the risks they are trying to control, or they are either too complicated or generic to effectively identify all areas of risk. An alternative approach one which will save more time in the long run and help identify risk more effectively is to interview the people requesting access first to better understand what they are trying to achieve. Armed with this information, you can then assess whether the same outcome could be achieved by limiting the data shared with the third party or by finding a way to secure the information before sharing it, for example by obfuscating data or encrypting it. Again, the idea is to start with the elements within your control your own data and how it is shared or encrypted, in transit and at rest. The benefit of this approach is that you may identify areas where existing or tweaked data controls or processes can avoid the need for investment in new systems. Third-party questionnaires absolutely have their place, but you need to make sure the questions are relevant, unambiguous and up to date. This leads us to the second part of the process, the management of workflows in third-party risk.Workflow management is a very important element of third-party risk. Understanding which risks are your highest, and therefore need to be addressed first is critical. Accidentally classifying a high risk as a low one could have a disproportionate impact on your business, so it is important to carefully review your criteria to make sure you are categorising risks correctly. It's also important to understand that risk triaging isn't static. Following completion of some of risk assessments, it may be found that a vendor or system initially classified as low risk has far more integration or connection to systems than initially identified and should therefore have their risk category upgraded. Managing risks in context and understanding the whole risk picture is essential to managing third-party risk as effectively as possible.Finally, the most important step is bringing it all together. It's easy to spend a great deal of money on managing third-party risk without seeing a great deal of return. Instead of just filling out questionnaires and recording the results, organizations should think about including further interviews and process reviews once they understand the full risk picture. Often, risks can be mitigated more effectively by better controlling access to data, rather than asking the third-party to manage the risk and creating a situation you don't have control over. Taking a holistic view and understanding which data and systems are connected enables you to continually lower the risks from third-parties and, as a bonus, enables business agility. And having an information security or risk management team that enables business agility can ultimately make a huge difference to the success of the business. ESManaging risks in context and understanding the whole risk picture is essential to managing third-party risk as effectively as possible
<
Page 8 |
Page 10 >