risk

Weak supplier security requirements and monitoring

Because supplier contracts omit security requirements and SLAs and third-party service delivery is not monitored, processors and sub-processors operate without equivalent, audited obligations, so third-party weaknesses and breaches propagate into the organization undetected.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

category
third_party
domain
  • Third-Party / Supply-Chain Risk
  • Governance, Policy & Oversight
taxonomy
  • iso-27005-vulnerability
  • nist-privacy-risk
inherent_rating
high

Details

risk_id
tprm-weak-supplier-oversight
category
third_party
likelihood
high
impact
medium
inherent_rating
high
treatment
mitigate
taxonomies
  • iso-27005-vulnerability
  • nist-privacy-risk

Source

No record-specific source URL is provided.

Connections