Publication Cover
EDPACS
The EDP Audit, Control, and Security Newsletter
Volume 54, 2016 - Issue 4
315
Views
0
CrossRef citations to date
0
Altmetric
Original Articles

Vendor Risk Assessment

Pages 19-26 | Published online: 18 Oct 2016
 

Abstract

This article seeks to draw the attention of the executive management of enterprises to the growing importance of vendor risk assessments. Given that modern enterprises outsource non-core processes and operations to business partners and vendors, it is immensely important that a thorough risk assessment is performed of all control aspects and at all times—before the outsourcing and continuing risk assessments. Regulators hold enterprises responsible for data leakages by business partners and vendors. Therefore, enterprises need to ensure that appropriate metrics for measurement of vendor and business partner performance is well laid out in the agreements with the vendors and business partners. Indicative reference framework such as COBIT 5 framework for vendor management, how we manage a cloud service provider and key risk assessment processes have been provided to assist the executive management. Third party audits of businesses and operations of key vendor and business partners need to be conducted.

Additional information

Notes on contributors

Latha Sunderkrishnan

Latha Sunderkrishnan (CISA, ISO27001 LA, COBIT 5 Foundation) is an Executive Director at Valsec solutions India, http://valsecsolutions.com/. She is an Electronics Engineer with more than 20 years of experience in IT with various multinational organizations working with a wide variety of technologies. She has worked in Information Security Audits and Consulting, Information Security trainings, Project Management, Quality Assurance, and Customer Support. She can be reached at [email protected] or lathasunderkrishnan.valsecsolutions.com

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.