Home > How to manage security risks in vendor contracts
Learning Guide:
EMAIL THIS

How to manage security risks in vendor contracts

15 Sep 2009 | SearchFinancialSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

By Andrew M. Baer, Esq., Contributor

Financial institutions are required by their regulators to evaluate and manage the risk associated with sharing non-public customer and consumer information with third-party vendors. Generally speaking, as a critical component of their overall information security program, they must implement and maintain vendor management policies and procedures that include: pre-contract due diligence to verify each vendor maintains reasonable and appropriate security protections; a written contract with the vendor that mandates use of such protections and optimally reserves certain other rights for the financial institution; and periodic monitoring of the vendor after the contract is signed to verify its security.

This learning guide from SearchFinancialSecurity.com focuses on the second element of vendor risk management: What needs to be in vendor contracts? Or, more precisely, what information security-related clauses should a financial institution include in its contracts with high-risk vendors (i.e., those who will have access to a significant amount of sensitive non-public personal information, such as names combined with account or Social Security numbers) to conform to regulatory guidance and industry best practices for managing vendor risk?


HOW TO MANAGE SECURITY RISKS IN VENDOR CONTRACTS

  Introduction
  Vendor contract management: Regulatory guidance is risk-based
  Vendor audit and monitoring contractual rights
  Data breach protection: Implementing vendor breach safeguards
  Vendor risk management: process and documentation


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Business partner and vendor security issues
New vendor risk assessment tools address cloud computing
Don't forget the cleaning crew in your vendor management program
Vendor contract management: Regulatory guidance is risk-based
Vendor audit and monitoring contractual rights
Data breach protection: Implementing vendor breach safeguards
Vendor risk management: process and documentation
Download presentations from Financial Information Security Decisions 2009
Advocacy group looks to foster trust in foreign service providers
Shared Assessments aims to ease third-party security evaluations
Security questions to ask SaaS vendors when outsourcing services

Compliance best practices
Regulators issue standardized privacy notice form for GLBA compliance
Seven GRC best practices for information security
Keeping up with state data protection laws
Five mistakes banks make in pandemic planning
Get ready for remote deposit capture risk management scrutiny
Google ordered to deactivate Gmail account after bank email error
Vendor risk management: process and documentation
How to streamline role-based access control
Five considerations for choosing network access control products
How to shift to centralized authentication and ease compliance

Risk management frameworks, metrics and strategy
Vendor risk management: process and documentation
Controls monitoring helps with governance, risk and compliance
An advancement in GRC
Advocacy group looks to foster trust in foreign service providers
Using an information security council
Information security governance using a risk-based approach
Security on the street with SearchFinancialSecurity.com: Risk management
Strategic metrics for information security at financial services firms
Metrics don't truly quantify information risk
Financial Information Security Decisions 2008: Presentation downloads

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Shared Assessments Program  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Find Expert White Papers on Financial Data Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts