Third Party Risk Management Services | IT Security Solutions
Text SizeFont Size is Currently SmallestIncrease Font Size   Print: Third Party Risk Management ServicesEmail: Third Party Risk Management ServicesDownload PDF: Third Party Risk Management ServicesSave: Third Party Risk Management Services
  • white papers
  • webinars
  • articles
  • news

Managing Third Party Risk
Some sources of risk that may not be top-of-mind include your service providers, web hosting services, contractors, outsourcers, supply-chain nodes, consulting services, and travel services—any number of outside entities having custody of or access to your sensitive information. If your extended enterprise includes these third parties, you need a way to manage this risk.

PDFTake the white paper (4.5MB)

Securing Your Constituents and Institutional Information
In this presentation of Security by Example by Carolyn Ryll, you will shake your heads at common mistakes, but learn how not to make them yourself.

Access the replay

Local Government Emergency Services: Setting Yourself Up for Success
This article, by CIBER’s A.J. Briding first appeared in IAEM Bulletin in October 2007

PDFTake the article

01 Mar 2010
CIBER Strategic Partnership with CNL Software Enhances CIBERSecure
Read the press release   | PDFTake the PDF (25KB)

16 Feb 2010
CIBER Selected for Integrated Port Security Project at Georgia Port Authority
Read the press release   | PDFTake the PDF (25KB)

  • client quote

“CIBER demonstrated outstanding experience working with other major cities, like the City of San Francisco, in creating strong e-Gov offerings that resulted in high citizen satisfaction. Based on their hands-on experience, 30-year history of successfully working with local governments and their commitment to creating a strong local presence, we selected CIBER as our strategic web management partner. We are confident CIBER has the expertise to help us develop a site and service offering that will benefit our citizens now and for years to come and place our City in the top tier of ‘best practices for City e-government web services’.”

Dr. Melodie Mayberry-Stewart — Chief Technology Officer, City of Cleveland

For more information about our Third Party Risk Management Services services & solutions, please contact:

303.963.2112
bbird@ciber.com

Bonnie Bird
Manager, Marketing

 

Third Party Risk Management Services

There is no contractual verbiage that absolves you of the responsibility and accountability for the security of the information residing with your vendors. It will be your name that clients remember a year after a security breach; not the name of your negligent vendor.

During 2007, it is estimated that as many as 5 pieces of sensitive customer data were lost or stolen every second amounting to more than 162.5 million records. One study, conducted over four years, found almost half of data breaches implicated business partners.

Extending Security Controls to Privileged Third Parties

Today’s extended enterprises include third parties and business partners that often have privileged access to your customers’ sensitive data. Examples include service providers, webhosting, data processing, contractors, outsourcers, supply-chain nodes, consulting services, and travel services.

Organizations have increasingly turned to service providers to supplement and complement service delivery and business operations. According to the IT Compliance Institute, the second most important movement in 2008 in IT security is extending security controls to privileged third parties. “Scores of information breaches have been tied to such privileged third parties over the past several years, but third-party security has generally remained peripheral to managerial focus. In the next year, managerial confidence in internal information security, coupled with ample documentation of policies and procedures, will allow managers to contractually enforce security controls across broader business relationships,” said Cass Brewer, Editor and Research Director for the IT Compliance Institute.

A program aimed at classifying and evaluating third party risk allows IT managers to monitor and verify security controls contracted to business vendors.

The CIBER Approach

Business functionality in our current information-driven world often requires sharing data with organizations and individuals that may include partners, service providers, and other organizations need to ensure that their data is protected, even when it is in the custody of a third party. Many of our clients network with of hundreds of third party vendors, and a large percentage of those have access to sensitive corporate information in one way or another. With CIBER’s Third Party Risk Management service, CIBER helps you identify and manage the risks associated with third parties.

CIBER’s turn-key service evaluates third-party vendors to determine:

  • which third parties interact with sensitive corporate data
  • how they are handling, protecting and securing your data—the data itself as well as the infrastructure processing, storing, or transmitting it
  • whether they maintain acceptable security controls, adhere to your security requirements, applicable regulations, and contractual obligations
  • the level of risk each third party represents to your company and/or your data.

All forms of sensitive data are addressed by this service including customer data, intellectual property, non-public personal information (NPPI), personally identifiable information (PII), sensitive personal information (SPI), electronic protected healthcare information (ePHI), credit card data, account information, and services and transaction data. For information covered by privacy and security regulations, CIBER’s service helps clients ensure that regulatory requirements are being fulfilled by their service providers and business partners.

Classifying, Evaluating and Correcting

The service begins with the classification of your vendors based on the sensitive data that is accessed, stored or processed as part of your business relationship. Next, CIBER evaluates the level of risk posed by each vendor. In this step, we evaluate the security practices of the third-party vendors to determine if they meet your security requirements or accepted standards, such as ISO 27002 or applicable regulations. With security issues documented, the Security Practice provides corrective actions to the vendor for reducing identified risks. Vendor remediation efforts are tracked to ensure the corrective actions are addressed satisfactorily. Since security is an ongoing process, CIBER’s service provides annual reviews of each vendor and updates their risk status.

The Third Party Risk Management service can be customized to meet business and security needs regardless of industry or business model. CIBER is currently performing Third Party Risk Management for clients in the banking, financial services, healthcare, and retail industries. We have performed similar risk assessments for other clients in the banking and government sectors.



Take it, share it...

For more detailed information, download the full version
(PDF, 318KB)

Text SizeFont Size is Currently SmallestIncrease Font Size   Print: Third Party Risk Management ServicesEmail: Third Party Risk Management ServicesDownload PDF: Third Party Risk Management ServicesSave: Third Party Risk Management Services

Services Quick Links:

TOP

CIBER USA   :  Services | ERP / Package Solutions | Industries | Case Studies & Resources | News & Events | About CIBER :: Contact Information
International  :  CIBER International | Global Locations    Employees :  Employee Resources | Recruiters | CIBERspace | CIBERstore | Password Reset

Newest Case Studies : The Investment Fund for Foundations  |  An International Cruise Line  |  Municipal Utility in Central Texas  :: more
Popular Case Studies : Mercedes Benz  |  MOPAR  |  An International Cruise Line  :: more
Newest White Paper  : Optimizing the Value Chain: Collaborative Customer Knowledge in Global Insurance   :: more
Newest Webinar  : Insurance Industry Webinar: Turn customer knowledge into profits   :: more


Visit other CIBER sites:  

RSS Feeds   CIBER on Twitter

© 2010 CIBER, Inc. — All Rights Reserved. Legal Notice | Privacy Policy | Corporate Governance | Website Feedback
CIBER, CIBERJOBS, CIBERspace and the CIBER logo are trademarks or registered trademarks of CIBER, Inc.
CIBER stock is publicly traded under the symbol "CBR" on the NYSE.