当前位置:首页 >英文主页 >中英对照 > 报告详情

UpGuard:2023网络安全供应商风险评估终极指南白皮书(英文版)(18页).pdf

上传人: 白**** 编号:140217 2023-09-13 18页 2.75MB

下载:

1、Trusted by hundreds of companies worldwideThe Ultimate Guide to Cybersecurity Vendor Risk AiiTable of ContentsIntroduction 1What is Vendor Risk Management?3How to Assess Third-Party Vendors 4What are the common challenges of third-party risk assessments?6Why You Should Combine Security Ratings with

2、Questionnaires 8UpGuard supports the Complete Scope of Vendor Risk Assessments 9 Conclusion 1IntroductionThe third-party landscape is a critical cyber-attack vector that cannot be ignored.There are 3 reasons for this.1.Third-party Vendor dont have a great reputation for cybersecurity.According to a

3、Gartner survey,52%of surveyed businesses said theyre concerned about third-party cybersecurity.2.Third-party vendors have access to a significant amount of your personal data.A study by the Wiz research team revealed that 82%of companies give third parties access to all of their cloud data.3.Third-p

4、arty vendors have access to a significant amount of your personal data.In recognizing the above two trends,cybercriminals have discovered a more convenient pathway to a business private data.Instead of challenging the often resilient security controls at a victims IT boundary,its much easier to comp

5、romise their data by breaching one of their vendors.Because businesses share such a considerable portion of their customer data with their vendors,and each vendor partners with multiple businesses,a single third-party breach could potentially result in the compromise of multiple businesses and their

6、 customers.Two famous examples of such a cyberattack are the SolarWind breach and the Accellion 2As youd expect,cybercriminals are rushing to exploit the considerable benefits of targeting the third-party landscape.51%of organizations experienced a data breach caused by a third party.83%of organizat

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了第三方风险管理(Vendor Risk Management, VRM)的重要性,以及如何有效地评估和管理第三方供应商的网络安全风险。文章指出,第三方供应商是网络攻击的重要途径,因为他们可能接触到大量的个人数据。文中提到,52%的受访企业对第三方供应商的网络安全表示担忧,82%的企业允许第三方访问所有云数据。 文章详细介绍了五种评估第三方风险的方法:安全评级、安全问卷、审查现有安全文档、渗透测试和虚拟及现场评估。同时,文章也指出了第三方风险评估中常见的挑战,如速度、深度、可见性、一致性、背景和可追溯性等。 为了解决这些问题,文章建议将安全评级与问卷调查相结合,以更全面、准确地评估每个第三方供应商的安全状况。此外,UpGuard提供了一个完整的供应商风险评估框架,包括安全评级、问卷调查和额外的证据,以支持整个风险评估过程。
如何有效管理第三方供应商风险? 如何结合安全评级和问卷进行风险评估? 如何确保第三方供应商的数据安全?
客服
商务合作
小程序
服务号
折叠