NuHarbor Security
  • Solutions
    Solutions
    Custom cybersecurity solutions that meet you where you are.
    • Overview
    • Our Approach
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • By Business Need
      • Identify Gaps in My Cybersecurity Plan
      • Detect and Respond to Threats in My Environment
      • Fulfill Compliance Assessments and Requirements
      • Verify Security With Expert-Led Testing
      • Manage Complex Cybersecurity Technologies
      • Security Monitoring With Splunk
    • By Industry
      • State & Local Government
      • Higher Education
      • Federal
      • Finance
      • Healthcare
      • Insurance
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Services
    Services
    Outcomes you want from a team of experts you can trust.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Security Testing
      • Penetration Testing
      • Application Penetration Testing
      • Vulnerability Scanning
      • Wireless Penetration Testing
      • Internal Penetration Testing
      • External Penetration Testing
    • Assessment & Compliance
      • CMMC Compliance
      • NIST 800-53
      • HIPAA Security Standards
      • ISO 27001
      • MARS-E Security Standards
      • New York Cybersecurity (23 NYCRR 500)
      • Payment Card Industry (PCI)
    • Advisory & Planning
      • Security Strategy
      • Incident Response Planning
      • Security Program Reviews
      • Security Risk Assessments
      • Virtual CISO
      • Policy Review
    • Managed Services
      • Curated Threat Intelligence
      • Managed Detection and Response (MDR)
      • Sentinel Managed Extended Detection and Response (MXDR)
      • SOC as a Service
      • Splunk Managed Services
      • Tenable Managed Services
      • Vendor Security Assessments
      • Vulnerability Management
      • Zscaler Support Services
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Partners
  • Resources
    Resources
    Explore reports, webinars, case studies, and more.
    • Browse Resources
    • Consultation Icon Consult with an expert
    • Blog icon Blog
    • Podcast icon Podcast
    • Annual SLED CPR icon Annual SLED CPR
    • Downloadable Assets icon Downloadable Assets
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Company
    Company
    We do cybersecurity differently – the right way.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Leadership
    • News
    • Careers
    • Contact
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Consult with an expert
  • Client support
  • Careers
  • Contact
1.800.917.5719
NuHarbor Security Blog
    • Compliance
    • Cybersecurity Technology
    • Security Operations
    • Industry Insights
    • Security Testing
    • Advisory and Planning
    • Application Security
    • Managed Detection and Response
    • Threat Intelligence
    • NuHarbor
    • Managed Services
    • Cyber Talent
September 19, 2018

Less is more: Focusing your third-party vendor risk assessments on the basics

Paul Dusini

CISOs, CIOs, and Risk Managers often understand the importance of vendor information security assessments but don’t know where to begin. I manage a team of analysts who perform vendor assessments, and we have experience making this process both successful and relatively painless.

The goal of your vendor security assessment program is to understand the overall risk posture of your strategic vendors, and therefore, risks to the confidentiality, integrity, or availability of your data. The first step in the process is to identify which vendors you should assess. We reviewed this process in a recent blog Risk Management – Which Vendors Should I Assess? After you have identified the vendors, the next step is to identify the information security controls you want to assess. Creating an assessment questionnaire to send to vendors will keep the focus of the assessment on the controls that matter most to your business.

Vendor assessment surveys do not need to ask hundreds of questions. Instead, to ensure that your assessment process is successful, keep it simple. Focus on key relevant security controls that are the foundation for a strong security posture and are relevant to your business. What are the core concepts and controls you need to understand to assess the security posture of a vendor? In our practice, we have narrowed it down to a core list of thirty-six questions that are grouped in the following categories.

  • Operational Security
  • Business Continuity
  • Physical Security
  • System Security
  • Access Controls
  • Data Security
  • Network Security
  • Application Development Security
Creating Your Own Questionnaire

To build your own set of questions, look at the control families within NIST 800-53 as a guide. Some of the control families can be grouped together and all families do not need to be included in your assessment of third parties. Notice that we divide our questions into just eight categories (we also include two privacy categories). After you have your categories, review the major controls in each related NIST control family to identify the questions you need. Focus on the basics. For instance, related to access controls we ask vendors to respond to five questions:

  • Please describe your access management procedures including support for role-based access control (RBAC) utilizing least privilege and separation of duties.
  • How often are account permissions reviewed?
  • Describe any additional security controls in place for the management of privileged accounts.
  • Describe any policies in place regulating the use of personal equipment to access the system.
  • If employees or contractors access systems remotely, describe any remote access security controls and polices in place.

You don’t need many questions to get a good sense of how well the vendor is doing in each category. If you can limit the number of assessment questions, you are more likely to get timely and well-developed responses from your vendors. Most vendors aren’t willing to respond to unnecessarily large questionnaires, and you wouldn’t want to review a long list of responses.

When Questionnaires Do Not Work

What if your vendor isn’t willing to fill out custom questionnaires? In these cases, vendors will submit SSAE16 SOC2 reports or other appropriate documentation to provide evidence. You can use your list of foundational control questions as a guide as you review the documentation. You want to find evidence that each of your key control areas has been addressed. If some questions are not evidenced in the documentation, we find that most vendors are willing to personally respond to a shorter list of follow-up questions via e-mail or phone.

Outsourcing Vendor Assessments

Our clients have chosen to outsource vendor risk assessments, and that choice often makes sense. This process is time consuming and using the experience of security professionals who do this regularly adds value to the results. If you choose to perform these assessments yourself, consider using our suggestions as you design your process. We have found the approach to be less painful for both vendors and reviewers, and we have discovered it yields more accurate and focused results. Keeping it simple will provide better insight into the overall security posture of your vendor and identify the most significant risks they bring to your business.

If you're looking for help with vendor assessments, please contact us today.
https://nuharborsecurity.com/vendor-assessments

Included Topics

  • Compliance,
  • Security Operations

Related Posts

Compliance 3 min read
Not your father’s controls - Keeping your vendor assessment process updated Read More
Security Operations 2 min read
Vendor risk assessments – Which methodology meets your needs? Read More
Security Operations 2 min read
Assessing Vendor Risk: Is Reviewing a SOC Report Enough? Read More

Subscribe via Email

Subscribe to our blog to get insights sent directly to your inbox.

Subscribe Here!

Latest Pwned episodes

Episode 200 - Reflections of Pwned...Until Next Time
April 03, 2024
Episode 200 - Reflections of Pwned...Until Next Time
Listen Now
Episode 199 - When a BlackCat Crosses Your Path...
March 21, 2024
Episode 199 - When a BlackCat Crosses Your Path...
Listen Now
Episode 198 - Heard it Through the Grapevine - Beyond the Beltway, 2024
March 08, 2024
Episode 198 - Heard it Through the Grapevine - Beyond the Beltway, 2024
Listen Now
NuHarbor Security logo
NuHarbor Security

553 Roosevelt Highway
Colchester, VT 05446

1.800.917.5719

  • Solutions
  • Services
  • Partners
  • Resources
  • Company
  • Contact
  • Privacy Policy
Connect
  • Twitter
  • Linkedin
  • YouTube
©2025 NuHarbor Security. All rights reserved.