Home > Services > IT Security > Third Party Risk Management Services
- solutions
- vertical solutions
- takeaway pdfs
Take them, share them...
Business Continuity and Disaster Recovery P... (936KB)
Emergency Management for Higher Education (297KB)
Emergency Management for Schools (325KB)
Emergency Management Services (PDF, 322KB)
Information Security Outsourcing (PDF, 364KB)
Information Security Services (PDF, 313KB)
IT Security for State & Local Government (PDF, 286KB)
IT Security in Higher Education (PDF, 176KB)
Security Assessment (PDF, 281KB)
Third Party Risk Management Services (PDF, 318KB)
- white papers
- webinars
- articles
- news
Managing Third Party Risk
Some sources of risk that may not be top-of-mind include your service providers,
web hosting services, contractors, outsourcers, supply-chain nodes, consulting
services, and travel services—any number of outside entities having custody
of or access to your sensitive information. If your extended enterprise includes
these third parties, you need a way to manage this risk.
Take the white paper (4.5MB)
Higher Education Disaster Readiness: Customizing Effective, Affordable Solutions
The increasing range and impact of threats to school systems today are driving
the requirement for higher education institutions to provide more comprehensive
and robust emergency readiness and response than has been expected of them
in the past. There is much to be done to create
emergency management programs that are effective.
Take the white paper (1MB)
Business Impact Analysis: Foundation For Operational Risk Management
This white paper explains the relationship of BIA to each of the elements of
operational risk management (ORM). It describes the components and process of BIA, and demonstrates how
BIA can be leveraged to drive ORM programs and expenditures. The intended
audience includes organizational senior managers, operational risk managers,
and functional managers.
Take the white paper (992KB)
IT Security Operational Maturity: Why You Need More Than Personal Heroism and Silver Bullets
This white paper illustrates the many business drivers shaping IT security, emerging
risks, and the need to transform your security program into one that’s operationally
mature. After reading this white paper, you’ll understand how to direct investments in
your organization’s IT security program to achieve security results that are consistent,
reliable, effective, affordable, and auditable.
Take the white paper (540KB)
Securing Your Constituents and Institutional Information
In this presentation of Security by Example by Carolyn Ryll, you will shake your heads at common mistakes, but learn how not to make them yourself.
Third Party Risk Management: Do your vendors protect your sensitive data as you would?
Join CIBER for a complimentary webinar that will illustrate ways in which your organization can identify and mitigate risks posed by those third party vendors who have access to your sensitive and mission-critical data as a normal course of doing business with you.
IT Security Operational Maturity: Imaginary Superheroes or Sound Solutions?
If your organization is relying on individual point solutions, personal heroism, or other “silver bullets” to secure its IT assets, it may be time to face the kryptonite.
Business Impact Analysis: Foundation for Operational Risk Management
This webinar will teach you ways in which your organization’s risk management activities can be enhanced by applying Business Impact Analysis (BIA) methodologies.
IT Security Maturity in Higher Education
Learn how to transform your institution’s security program into an operationally mature program that permanently reduces risk.
Local Government Emergency Services: Setting
Yourself Up for Success
This article, by CIBER’s A.J. Briding first appeared in IAEM Bulletin in
October 2007
Local
Government Emergency Services: Partnering With Your IT Department
This article, by CIBER’s A.J. Briding first appeared in IAEM Bulletin in August 2007
Local Government Emergency Services: The Necessity for Thoroughness
This article, by CIBER’s A.J. Briding and Jerry Sneed, Director, Office of Emergency Preparedness, City of New Orleans, first appeared in IAEM Bulletin in February 2007
01 Mar 2010
CIBER Strategic Partnership with CNL Software Enhances CIBERSecure
Read the press release |
Take the PDF (25KB)
16 Feb 2010
CIBER Selected for Integrated Port Security Project at Georgia Port Authority
Read the press release |
Take the PDF (25KB)
09 Nov 2009
CIBER Completes Database and Reporting System for the Investment Fund for Foundations (TIFF)
Read the press release |
Take the PDF (25KB)
07 Oct 2009
CIBER Wins $14 Million Security Contract with New International Port, Misurata Free Zone, Libya
Read the press release |
Take the PDF (25KB)
24 Jun 2009
CIBER Announces Contract Renewal and Expansion With Gate Gourmet
Read the press release |
Take the PDF (25KB)
21 May 2009
CIBER Goes Live With Four University PeopleSoft Admission and Financial Aid Implementations
Read the press release |
Take the PDF (25KB)
20 Apr 2009
CIBER Announces Five-Year Outsourcing Contract Renewal With Sharp Electronics
Read the press release |
Take the PDF (25KB)
24 Mar 2009
CIBER and Deluxe to Present at Boston SecureWorld Conference
Read the press release |
Take the PDF (25KB)
03 Nov 2008
CIBERSecure Enables Coordinated Security Response For Command and Control Centers
Read the press release |
Take the PDF (25KB)
08 Oct 2008
Denver Public Schools Selects CIBER for Human Resources Business Transformation
Read the press release |
Take the PDF (25KB)
22 Jul 2008
CIBER Partners with Carnegie Mellon University’s Software Engineering Institute to Provide Training Services
Read the press release |
Take the PDF (25KB)
12 Jun 2008
CIBER Consultant A.J. Briding Earns Top Certification in Organizational Resilience
Read the press release |
Take the PDF (25KB)
- client quote
“CIBER demonstrated outstanding experience working with other major cities, like the City of San Francisco, in creating strong e-Gov offerings that resulted in high citizen satisfaction. Based on their hands-on experience, 30-year history of successfully working with local governments and their commitment to creating a strong local presence, we selected CIBER as our strategic web management partner. We are confident CIBER has the expertise to help us develop a site and service offering that will benefit our citizens now and for years to come and place our City in the top tier of ‘best practices for City e-government web services’.”
Dr. Melodie Mayberry-Stewart — Chief Technology Officer, City of Cleveland
Security blog
Manage Operational Risk Like a Bank!
posted: 08 June 2009 by Eric Tompkins
IT Assessment Cost vs. Value – A Market Response Analysis
posted: 06 May 2009 by Matthew Sharp
For more information about our Third Party Risk Management Services services & solutions, please contact:
bbird@ciber.com
Bonnie Bird
Manager, Marketing
Third Party Risk Management Services
There is no contractual verbiage that absolves you of the responsibility and accountability for the security of the information residing with your vendors. It will be your name that clients remember a year after a security breach; not the name of your negligent vendor.
During 2007, it is estimated that as many as 5 pieces of sensitive customer data were lost or stolen every second amounting to more than 162.5 million records. One study, conducted over four years, found almost half of data breaches implicated business partners.
Extending Security Controls to Privileged Third Parties
Today’s extended enterprises include third parties and business partners that often have privileged access to your customers’ sensitive data. Examples include service providers, webhosting, data processing, contractors, outsourcers, supply-chain nodes, consulting services, and travel services.
Organizations have increasingly turned to service providers to supplement and complement service delivery and business operations. According to the IT Compliance Institute, the second most important movement in 2008 in IT security is extending security controls to privileged third parties. “Scores of information breaches have been tied to such privileged third parties over the past several years, but third-party security has generally remained peripheral to managerial focus. In the next year, managerial confidence in internal information security, coupled with ample documentation of policies and procedures, will allow managers to contractually enforce security controls across broader business relationships,” said Cass Brewer, Editor and Research Director for the IT Compliance Institute.
A program aimed at classifying and evaluating third party risk allows IT managers to monitor and verify security controls contracted to business vendors.
The CIBER Approach
Business functionality in our current information-driven world often requires sharing data with organizations and individuals that may include partners, service providers, and other organizations need to ensure that their data is protected, even when it is in the custody of a third party. Many of our clients network with of hundreds of third party vendors, and a large percentage of those have access to sensitive corporate information in one way or another. With CIBER’s Third Party Risk Management service, CIBER helps you identify and manage the risks associated with third parties.
CIBER’s turn-key service evaluates third-party vendors to determine:
- which third parties interact with sensitive corporate data
- how they are handling, protecting and securing your data—the data itself as well as the infrastructure processing, storing, or transmitting it
- whether they maintain acceptable security controls, adhere to your security requirements, applicable regulations, and contractual obligations
- the level of risk each third party represents to your company and/or your data.
All forms of sensitive data are addressed by this service including customer data, intellectual property, non-public personal information (NPPI), personally identifiable information (PII), sensitive personal information (SPI), electronic protected healthcare information (ePHI), credit card data, account information, and services and transaction data. For information covered by privacy and security regulations, CIBER’s service helps clients ensure that regulatory requirements are being fulfilled by their service providers and business partners.
Classifying, Evaluating and Correcting
The service begins with the classification of your vendors based on the sensitive data that is accessed, stored or processed as part of your business relationship. Next, CIBER evaluates the level of risk posed by each vendor. In this step, we evaluate the security practices of the third-party vendors to determine if they meet your security requirements or accepted standards, such as ISO 27002 or applicable regulations. With security issues documented, the Security Practice provides corrective actions to the vendor for reducing identified risks. Vendor remediation efforts are tracked to ensure the corrective actions are addressed satisfactorily. Since security is an ongoing process, CIBER’s service provides annual reviews of each vendor and updates their risk status.
The Third Party Risk Management service can be customized to meet business and security needs regardless of industry or business model. CIBER is currently performing Third Party Risk Management for clients in the banking, financial services, healthcare, and retail industries. We have performed similar risk assessments for other clients in the banking and government sectors.
Take it, share it...
For more detailed information, download the full version
(PDF, 318KB)





