<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accessing third party-vendor in Member Support</title>
    <link>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33165#M7096</link>
    <description>&lt;P&gt;Most of the vendors are SAAS providers, the data is mostly health related information.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2020 02:48:37 GMT</pubDate>
    <dc:creator>ylomax</dc:creator>
    <dc:date>2020-02-27T02:48:37Z</dc:date>
    <item>
      <title>Accessing third party-vendor</title>
      <link>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33160#M7093</link>
      <description>&lt;P&gt;Does anybody know where I find a relative inexpensive tool to use for third party vendor assessment? Qualys has one within the tool but it's $4000.00 any my boss not sure he wants to pay for that right now? if not a toll maybe even a good excel sheet with questions that are not too many but serve the purpose? questions dealing with 270001, SOC 1 type 11, HIPPA etc.….&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 01:40:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33160#M7093</guid>
      <dc:creator>ylomax</dc:creator>
      <dc:date>2020-02-27T01:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing third party-vendor</title>
      <link>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33164#M7095</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/135874465"&gt;@ylomax&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Does anybody know where I find a relative inexpensive tool to use for third party vendor assessment? Qualys has one within the tool but it's $4000.00 any my boss not sure he wants to pay for that right now? if not a toll maybe even a good excel sheet with questions that are not too many but serve the purpose? questions dealing with 270001, SOC 1 type 11, HIPPA etc.….&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Tell us more about the scope of the third-party vendor "engagement". The type of data involved and whether or not you procuring COTS, SaaS, or something other Cloud service.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 02:31:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33164#M7095</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-02-27T02:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing third party-vendor</title>
      <link>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33165#M7096</link>
      <description>&lt;P&gt;Most of the vendors are SAAS providers, the data is mostly health related information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 02:48:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33165#M7096</guid>
      <dc:creator>ylomax</dc:creator>
      <dc:date>2020-02-27T02:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing third party-vendor</title>
      <link>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33167#M7097</link>
      <description>&lt;P&gt;You need to make a distinction between what you're assessing; the vendors general approach to security or the security of the specific services that you're buying from them, as that should guide how you go about it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you look at it in terms of the source of assurance you can use that may help:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 Supplier assertion - The supplier asserts in the sales material, service descriptions, marketing and in verbal representations that their service is secure (Low)&lt;BR /&gt;2 Contractual Commitment - The supplier commits contractually to operate specific security controls and follow good industry practice (High)&lt;BR /&gt;3 Off site supplier assessment - The suppliers answers a standardised questionnaire, provides supporting documentary evidence requested and may also demonstrate aspect of their security via Webex, Skype or similar technology. (Medium)&lt;BR /&gt;4 On site supplier assessment - The suppliers answers a standardised questionnaire and allows an on site assessment by a security auditor, providing opportunity to observe operation of controls and/or view systems and documentation. (High)&lt;BR /&gt;5 Architectural Review A qualified and experienced security architect reviews the architectural design of the service(s) to ensure that they are designed to be technically secure (Medium/Low)&lt;BR /&gt;6 Service is built from known secure components - A security architect or auditor reviews the certifications and/or audit reports on the technical components making up the service (Low)&lt;BR /&gt;7 Previous Auditor Work - Independent auditors, including certification auditors have previously and recently audited the suppliers service(s) and ISMS and issued either a certificate or unqualified opinion as to it’s security High&lt;BR /&gt;8 Independent Penetration Test - An independent penetration test of the service(s) is either carried out by your organisation, its chosen external pen test company or a recent independent CHECK/CREST pen test report is provided by the supplier. (Medium)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there are multiple methods.&amp;nbsp; You might also want to look at the CSAs STAR scheme.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 10:08:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33167#M7097</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2020-02-27T10:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing third party-vendor</title>
      <link>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33173#M7098</link>
      <description>Thanks-you for your response.</description>
      <pubDate>Thu, 27 Feb 2020 13:37:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Accessing-third-party-vendor/m-p/33173#M7098</guid>
      <dc:creator>ylomax</dc:creator>
      <dc:date>2020-02-27T13:37:59Z</dc:date>
    </item>
  </channel>
</rss>

