This conversation launches at ISC2 Congress on Monday afternoon where I discuss various options for organizations to monitor internal operations of their most critical third party service providers.
Third Party Risk Management (TPRM) is a "thing" now. It's a relatively new topic that requires CISOs to allocate resources to do a better job of identifying and managing risks in third party organizations that provide products or services to an organization. TPRM operations can be very time consuming but there are platforms and tools that can help make the job easier and save costs as well.
Full disclosure: my employer has one such service, known as Evantix. More info here. (full link: https://www.optiv.com/solutions/third-party-risk-management/evantix)
However, my talk is not a sales pitch - I will barely mention Evantix, if at all.
See you at my session, and let's continue this afterwards.
Peter
Peter H Gregory | Executive Director – CISO Services
CISSP, CISA, CISM, CRISC, C-CISO, CCSK, PCI-QSA
peter.gregory@optiv.com
www.optiv.com
Peter H Gregory | Senior Director – Cyber GRC
CISSP, CISA, CISM, CRISC, CDPSE, CIPM, CCSK, DRCE
pgregory@gci.com
www.gci.com