Home > Services > IT Security > Third Party Risk Management Services
- solutions
- Industry solutions
- takeaway pdfs
Take them, share them...
Business Continuity and Disaster Recovery P... (936KB)
Emergency Management for Higher Education (297KB)
Emergency Management for Schools (325KB)
Emergency Management Services (PDF, 322KB)
Information Security Outsourcing (PDF, 364KB)
Information Security Services (PDF, 313KB)
IT Security for State & Local Government (PDF, 286KB)
IT Security in Higher Education (PDF, 176KB)
Security Assessment (PDF, 281KB)
Third Party Risk Management Services (PDF, 318KB)
- white papers
- webinars
- articles
- news
Managing Third Party Risk
Some sources of risk that may not be top-of-mind include your service providers,
web hosting services, contractors, outsourcers, supply-chain nodes, consulting
services, and travel services—any number of outside entities having custody
of or access to your sensitive information. If your extended enterprise includes
these third parties, you need a way to manage this risk.
Take the white paper (4.5MB)
Business Impact Analysis: Foundation For Operational Risk Management
This white paper explains the relationship of BIA to each of the elements of
operational risk management (ORM). It describes the components and process of BIA, and demonstrates how
BIA can be leveraged to drive ORM programs and expenditures. The intended
audience includes organizational senior managers, operational risk managers,
and functional managers.
Take the white paper (992KB)
Securing Your Constituents and Institutional Information
In this presentation of Security by Example by Carolyn Ryll, you will shake your heads at common mistakes, but learn how not to make them yourself.
Third Party Risk Management: Do your vendors protect your sensitive data as you would?
Join CIBER for a complimentary webinar that will illustrate ways in which your organization can identify and mitigate risks posed by those third party vendors who have access to your sensitive and mission-critical data as a normal course of doing business with you.
IT Security Operational Maturity: Imaginary Superheroes or Sound Solutions?
If your organization is relying on individual point solutions, personal heroism, or other “silver bullets” to secure its IT assets, it may be time to face the kryptonite.
Business Impact Analysis: Foundation for Operational Risk Management
This webinar will teach you ways in which your organization’s risk management activities can be enhanced by applying Business Impact Analysis (BIA) methodologies.
IT Security Maturity in Higher Education
Learn how to transform your institution’s security program into an operationally mature program that permanently reduces risk.
Local Government Emergency Services: Setting
Yourself Up for Success
This article, by CIBER’s A.J. Briding first appeared in IAEM Bulletin in
October 2007
Local
Government Emergency Services: Partnering With Your IT Department
This article, by CIBER’s A.J. Briding first appeared in IAEM Bulletin in August 2007
Local Government Emergency Services: The Necessity for Thoroughness
This article, by CIBER’s A.J. Briding and Jerry Sneed, Director, Office of Emergency Preparedness, City of New Orleans, first appeared in IAEM Bulletin in February 2007
16 Nov 2011
CIBER Wins Bid to Revamp Customer Service Systems for Security Service, Eighth Largest Credit Union in the U.S.
Read the press release |
Take the PDF (25KB)
04 Apr 2011
Internal Revenue Service Selects Contractors for Total Information Processing Support Services TIPSS-4 Information Technology Services (ITS)
Read the press release |
Take the PDF (25KB)
21 Feb 2011
CIBER Promotes Business of Healthcare Organizations;
Read the press release |
Take the PDF (25KB)
21 Feb 2011
Horizon Healthcare Services, Inc and CIBER Partner to Deliver Enterprise Mobile Framework Automating National Account Sales Process
Read the press release |
Take the PDF (25KB)
07 Feb 2011
Tim Montgomery to Head CIBER’s North American Delivery Operations
Read the press release |
Take the PDF (25KB)
01 Feb 2011
TIBCO's tibbr Chosen by CIBER Inc. as Social Computing Software for the Enterprise
Read the press release |
Take the PDF (25KB)
06 Dec 2010
CIBER Selected for Enhanced Perimeter Waterfront and Shore Surveillance Intrusion System Project at Virginia Port Authority Norfolk International Terminal
Read the press release |
Take the PDF (25KB)
15 Nov 2010
CIBER Wins IT Infrastructure Contract with Centers For Disease Control And Prevention
Read the press release |
Take the PDF (25KB)
05 Nov 2010
Alterian and CIBER Partner to Deliver Enhanced Digital Marketing Platform
Read the press release |
Take the PDF (25KB)
15 Oct 2010
CIBER Wins Contract with Eurofresh Farms to Implement Oracle’s JD Edwards EnterpriseOne
Read the press release |
Take the PDF (25KB)
14 Oct 2010
CIBER Wins Multi-Million Dollar Outsourcing Contract with Nashville Electric Service
Read the press release |
Take the PDF (25KB)
01 Oct 2010
CIBER Opens Technology Center, Adds 150 Jobs In Detroit
Read the press release |
Take the PDF (25KB)
- client quote
“CIBER demonstrated outstanding experience working with other major cities, like the City of San Francisco, in creating strong e-Gov offerings that resulted in high citizen satisfaction. Based on their hands-on experience, 30-year history of successfully working with local governments and their commitment to creating a strong local presence, we selected CIBER as our strategic web management partner. We are confident CIBER has the expertise to help us develop a site and service offering that will benefit our citizens now and for years to come and place our City in the top tier of ‘best practices for City e-government web services’.”
Dr. Melodie Mayberry-Stewart — Chief Technology Officer, City of Cleveland
| Tweet |
Third Party Risk Management Services
There is no contractual verbiage that absolves you of the responsibility and accountability for the security of the information residing with your vendors. It will be your name that clients remember a year after a security breach; not the name of your negligent vendor.
During 2007, it is estimated that as many as 5 pieces of sensitive customer data were lost or stolen every second amounting to more than 162.5 million records. One study, conducted over four years, found almost half of data breaches implicated business partners.
Extending Security Controls to Privileged Third Parties
Today’s extended enterprises include third parties and business partners that often have privileged access to your customers’ sensitive data. Examples include service providers, webhosting, data processing, contractors, outsourcers, supply-chain nodes, consulting services, and travel services.
Organizations have increasingly turned to service providers to supplement and complement service delivery and business operations. According to the IT Compliance Institute, the second most important movement in 2008 in IT security is extending security controls to privileged third parties. “Scores of information breaches have been tied to such privileged third parties over the past several years, but third-party security has generally remained peripheral to managerial focus. In the next year, managerial confidence in internal information security, coupled with ample documentation of policies and procedures, will allow managers to contractually enforce security controls across broader business relationships,” said Cass Brewer, Editor and Research Director for the IT Compliance Institute.
A program aimed at classifying and evaluating third party risk allows IT managers to monitor and verify security controls contracted to business vendors.
The CIBER Approach
Business functionality in our current information-driven world often requires sharing data with organizations and individuals that may include partners, service providers, and other organizations need to ensure that their data is protected, even when it is in the custody of a third party. Many of our clients network with of hundreds of third party vendors, and a large percentage of those have access to sensitive corporate information in one way or another. With CIBER’s Third Party Risk Management service, CIBER helps you identify and manage the risks associated with third parties.
CIBER’s turn-key service evaluates third-party vendors to determine:
- which third parties interact with sensitive corporate data
- how they are handling, protecting and securing your data—the data itself as well as the infrastructure processing, storing, or transmitting it
- whether they maintain acceptable security controls, adhere to your security requirements, applicable regulations, and contractual obligations
- the level of risk each third party represents to your company and/or your data.
All forms of sensitive data are addressed by this service including customer data, intellectual property, non-public personal information (NPPI), personally identifiable information (PII), sensitive personal information (SPI), electronic protected healthcare information (ePHI), credit card data, account information, and services and transaction data. For information covered by privacy and security regulations, CIBER’s service helps clients ensure that regulatory requirements are being fulfilled by their service providers and business partners.
Classifying, Evaluating and Correcting
The service begins with the classification of your vendors based on the sensitive data that is accessed, stored or processed as part of your business relationship. Next, CIBER evaluates the level of risk posed by each vendor. In this step, we evaluate the security practices of the third-party vendors to determine if they meet your security requirements or accepted standards, such as ISO 27002 or applicable regulations. With security issues documented, the Security Practice provides corrective actions to the vendor for reducing identified risks. Vendor remediation efforts are tracked to ensure the corrective actions are addressed satisfactorily. Since security is an ongoing process, CIBER’s service provides annual reviews of each vendor and updates their risk status.
The Third Party Risk Management service can be customized to meet business and security needs regardless of industry or business model. CIBER is currently performing Third Party Risk Management for clients in the banking, financial services, healthcare, and retail industries. We have performed similar risk assessments for other clients in the banking and government sectors.
Take it, share it...
For more detailed information, download the full version
(PDF, 318KB)

