Chapter 7On‐site Due Diligence
The act of going to a vendor site and performing due diligence is an investment in time, resources, and money, and is best left for vendors that a company has determined require this level of commitment. KC Enterprises reserves on‐site assessments for high‐risk vendors and moderate‐risk ones that meet a certain risk category. Vendors with data in a Cloud Service Provider (CSP), such as Google, Azure, or AWS, also will get on‐site assessment due to the risks surrounding the Shared Responsibility model.
The system of record notes both the risk level and last on‐site due diligence visit when required. KC averages 50 vendors in the high‐risk category year after year and another 10 in moderate risk who fit the criteria for a trip to the vendor directly. As business operates normally, some third parties are dropped for others or their relationship changes and they drop to a lower risk category.
This due diligence effort intentionally stays away from checklists. The visit to the vendor, where you are physically at their location and having eye contact with them, is an opportunity that a checklist sent via a portal cannot provide. The purpose and training of the senior analysts who perform this verification visit are taught primarily through on‐the‐job training with leadership emphasis on vendors as partners. (More about job training for this KC role will be discussed later on.)
On‐site Security Assessment
There are five phases to the On‐site assessment: ...
Get Cybersecurity and Third-Party Risk now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.