Third-Party Assessments and Monitoring

3 slides · 2 min read · Domain 1

Third-Party Assessments and Monitoring

It is imperative that an organization apply the same risk-management methodologies and perspectives to its supply chain as the organization did for its own internal operations.

This may include the organization performing the following for each entity within the supply chain:

GOVERNANCE REVIEW

FORMAL SECURITY AUDIT

SITE SECURITY SURVEY

PENETRATION TESTING

However, in many cases, this is untenable, and sometimes it can create additional liability issues for both parties. Instead, organizations often rely on audit reports prepared by certified third parties to properly evaluate the entities within the organization's supply chain.

This has notably been the case with managed cloud services, where the cloud customer often does not even know the | physical location of the cloud data center and must rely on external validation of the provider's security.

There are a variety of standards • AICPASSAE 16 SOC reports

The American Institute of Certified

and audit methodologies

Public Accountants (AICPA) created

for assessing the security of

the Statement on Standards of external organizations.

Attestation Engagements (SSAE) 16 These include but are not standard as a response to prevailing federal legislation in the United limited to the following:

States (specifically, the SarbanesOxley Act, referred to as SOX). The SSAE 16 standard details three types

  • CSA STAR evaluation: As mentioned

of reports intended for different uses;

previously, the Cloud Security Alliance these are the SOC reports. The SSAE offers a registration program for cloud

20 SOC 1,2,3 are highly regarded providers called STAR. It can be selfassurance reports. While the SSAE 16 administered by the target organization standard is designed for publicly traded or conducted by a certified external corporations, it has come into wide use auditor, depending on the STAR Level by organizations of all types.

the target organization seeks.

  • ISO-certified audits: Each ISO standard can be assessed by an accredited auditor, and the target organization can earn certification by successfully passing this audit.
Test this domain