How to manage security risks in vendor contracts

How to manage security risks in vendor contracts

By Andrew M. Baer, Esq., Contributor

    Requires Free Membership to View

    SearchFinancialSecurity.com members gain immediate and unlimited access to in-depth technical advice, strategies, and expert guides for securing data in high-risk financial environments. Join me on SearchFinancialSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchFinancialSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchFinancialSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Financial institutions are required by their regulators to evaluate and manage the risk associated with sharing non-public customer and consumer information with third-party vendors. Generally speaking, as a critical component of their overall information security program, they must implement and maintain vendor management policies and procedures that include: pre-contract due diligence to verify each vendor maintains reasonable and appropriate security protections; a written contract with the vendor that mandates use of such protections and optimally reserves certain other rights for the financial institution; and periodic monitoring of the vendor after the contract is signed to verify its security.

This learning guide from SearchFinancialSecurity.com focuses on the second element of vendor risk management: What needs to be in vendor contracts? Or, more precisely, what information security-related clauses should a financial institution include in its contracts with high-risk vendors (i.e., those who will have access to a significant amount of sensitive non-public personal information, such as names combined with account or Social Security numbers) to conform to regulatory guidance and industry best practices for managing vendor risk?


HOW TO MANAGE SECURITY RISKS IN VENDOR CONTRACTS

  Introduction
  Vendor contract management: Regulatory guidance is risk-based
  Vendor audit and monitoring contractual rights
  Data breach protection: Implementing vendor breach safeguards
  Vendor risk management: process and documentation

This was first published in September 2009