risk
Weak supplier security requirements and monitoring
Because supplier contracts omit security requirements and SLAs and third-party service delivery is not monitored, processors and sub-processors operate without equivalent, audited obligations, so third-party weaknesses and breaches propagate into the organization undetected.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- third_party
- domain
- Third-Party / Supply-Chain Risk
- Governance, Policy & Oversight
- taxonomy
- iso-27005-vulnerability
- nist-privacy-risk
- inherent_rating
- high
Details
- risk_id
- tprm-weak-supplier-oversight
- category
- third_party
- likelihood
- high
- impact
- medium
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-01 — Operate a third-party security risk management program mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Embedding security requirements and audit/access rights, reviewing service agreements and supplier performance, and reassessing on a cycle directly counters unmonitored, unbound suppliers.
- UC-GOV-20 — Govern data as an asset with accountable oversight bodies mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Reviewing and approving data-sharing and matching agreements controls data exposed to third parties.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Binding required security controls, audit rights, and breach-notification terms into supplier contracts directly supplies the security requirements the risk says are missing.
- UC-TPRM-06 — Manage secure termination and disposal at relationship end mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Access revocation and verified data return at termination reduce the residual-access breach vector but supply neither the security requirements nor the ongoing monitoring the risk describes, so the effect is contributory.
- UC-TPRM-08 — Govern security of external and cloud service use mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Requiring external and cloud providers to comply with infosec requirements and monitoring their compliance on an ongoing basis directly counters unmonitored external providers.
- UC-TPRM-05 — Include suppliers in incident notification and response mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Supplier incident-notification obligations address the undetected-breach-propagation tail but not the missing-requirements or unmonitored-delivery core, so they contribute to rather than operate the oversight defense.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Pre-engagement security-posture due diligence screens weaker suppliers at selection but does not itself impose contractual security requirements or ongoing monitoring, so it contributes to rather than operating the oversight defense.
- UC-ACCESS-21 — Manage subservice organizations supporting the system mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Identifying, contractually binding, and monitoring subservice orgs via their assurance reports and CUECs directly closes the unmonitored, unbound third-party gap this risk describes.
- UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Evaluation criteria for externally developed applications set security requirements on acquired third-party software.
- UC-TPRM-04 — Monitor vendor performance, services, and risk mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Continuously monitoring third-party service delivery and security posture with periodic reassessment is precisely the monitoring the risk says is absent.