
In this lecture I’ll introduce the course, explain its benefits and discuss the target audience.
In this lecture I will provide a summary of the course structure and give you a “taster” of each section.
In this lecture I will the background story to “Cyber”, starting with “computer security” and providing the current context for cyber within third party risk.
In this lecture I will explain the important concept of due diligence, as the key approach to assessing the cyber capability of your organisation’s third parties.
In the last lecture in this section I will provide examples of several high profile security breaches attributed to third party cyber weaknesses. I will provide some takeaways common issues with these real world examples.
The first lecture in this topic focusses on explaining the GDPR requirements relating to use of third parties. For most UK and EU organisations, and any handling EU personal data, this will be the most prevalent regulation to mandate assessing cyber third party risk.
This lecture explains this new EU regulation, because it mandates rigorous assessments of a vendor's cybersecurity posture, making it crucial to evaluate potential risks when engaging with third-party providers.
This lecture explains the regulation which is considered the first EU-wide law focused on cyber security for a range of critical industry sectors and critical service providers.
In the first of two lectures on security standards, I will cover Cyber Essentials and ISO 27001. You will learn about the basics of these standards, certification and interpreting the certificates for your third party risk reviews.
In the second lecture on security standards, you will learn the basics about the Payment Card Industry Data Security Standard, which is relevant to many third parties. I will also discuss the differences between third parties aligning with standards and gaining certification.
In this lecture I will explain why a policy is important for your organisation, and you will learn what this policy should include.
In this lecture you will learn why having appropriate cyber security clauses within third party contracts is so essential, and I will explain what clauses to be included.
I will explain why assessing the inherent risk of a third party is important for your organisation, as a pre-curser to due diligence, and how details of the service provided, and use of the “CIA Triad” contribute to this assessment.
Learn about how the access that third parties have to your organisation’s systems contributes towards the inherent risk assessment.
In this lecture I will provide several examples of third parties from different industry sectors and show how their inherent risk can be been assessed.
In this lecture, the first of several of this topic, I will discuss how to choose an appropriate level of due diligence based on the inherent risk outcome.
In this lecture I will discuss use of the widespread SIG or “Standardized Information Gathering” questionnaire from the Shared Assessments organization.
In this lecture I will explain the benefits of using Security Ratings tools in your third party due diligence.
In the first of three lectures on SOC 2 reports I will explain the background, usage and relevant terminology surrounding SOC reports, and why SOC 2 reports are usually very beneficial to your organisation’s third party due diligence review.
In the second of the three lectures on SOC 2 reports, you will learn about the structure of the SOC 2 report, the 5 Trust Service Criteria, and shown working examples of the various sections of the report
In the last lecture on SOC 2 reports, I will provide some deeper insights into a report, checking its relevance to your organisation, and what things to look out for to get assurance about the report
In this lecture I will provide some guidelines and tips in designing your organisation’s own third party cyber questionnaire, to elicit the best responses from your third parties.
In the last lecture of this topic on due diligence I will explain the benefits of conducting a third party site visit, and planning tips to ensure you get the most out of the visit.
In this lecture I will explain what steps need to be taken if your due diligence review of a third party identifies inadequate security measures and control gaps. This includes working with your third party to create a suitable remediation plan, and addressing difficulties in achieving a satisfactory plan.
I'll provide you with access to download all the course resources, allowing you to keep valuable materials for future reference.
Understand why Cyber Security Third Party Risk Management is so important for organisations and what steps your organisation needs to take.
You will get a firm grasp of the cyber security third party risk today’s organisations face and what steps organisations and industries like yours can take to help manage this risk and protect themselves.
· Gain a solid understanding of the background and context to Cyber Security Third Party Risk, by looking at the Cyber Security and Third Party Risk backgrounds, and how they “meld” together.
· Learn about the importance of cyber security third party risk for organisations, and see how some of the latest high profile security breaches on organisations have been a result of their third party relationships
· Learn how to assess cyber security third party risk associated with your suppliers and the services their provide. Understand the concepts of Inherent Risk how to assess this using "CIA Triad" of confidentiality , integrity and availability and how we can use these to prioritise due diligence activities.
· Learn what key standards and regulations require organisations to do regarding cyber security third party risk, including ISO 27000, PCI DSS, Cyber Essentials, the GDPR, DORA and NIS 2.
· Learn about the different approaches to undertake due diligence of your third party’s cyber security posture, including design tips for custom questionnaires, and how to gain the most from SOC 2 reports and third party ISO 27001 certifications.
· Learn about the importance of legal contracts in addressing cyber security third party risk, and the importance of contract negotiation
· Understand and see samples of the documentation your cyber security third party risk management programme will require including samples of policy, procedures and templates.
· Learn about the importance of communications with suppliers and key stakeholders during the cyber risk third party risk management lifecycle, and how to manage the remediation of gaps within your third party’s security controls measures.