Skip to Content
Cybersecurity and Third-Party Risk
book

Cybersecurity and Third-Party Risk

by Gregory C. Rasner
July 2021
Intermediate to advanced
480 pages
9h 38m
English
Wiley
Content preview from Cybersecurity and Third-Party Risk

Chapter 11Cybersecurity and Legal Protections

Cybersecurity third‐party risk is not confined to due diligence efforts and security evaluations. One of the key components of lowering cybersecurity risk as a company is to use contract language that addresses this risk. This is not to say that cybersecurity professionals need to be attorneys as well to their respective firms; rather a cybersecurity team must be prescriptive to the legal team about what security controls need to be met by vendors prior to contract signatures and execution. Cybersecurity begins with defining the security standards for third parties—the criteria for when cybersecurity language is appropriate. Then, those definitions are taken further by defining criteria of when cybersecurity is engaged for legal terms and conditions; there must be a clear definition of how the process is completed, and the process defined for when there is a Risk Acceptance (RA) for any item(s) that presents a risk to the organization.

Legal Terms and Protections

Starting with a Security Standard or Policy, the cybersecurity team lays out exactly what a vendor is required to meet. While the actions surrounding this have been covered in previous chapters, this chapter discusses the legal terms and protections that cover the domains of access management, encryption, vulnerability management, patching cadence, right to perform audits/assessments, privacy, data center security, and so on. As the standards are written, they are linked ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Cybersecurity Risk Management

Cybersecurity Risk Management

Cynthia Brumfield, Brian Haugli
Building a Cyber Risk Management Program

Building a Cyber Risk Management Program

Brian Allen, Brandon Bapst, Terry Allan Hicks

Publisher Resources

ISBN: 9781119809555Purchase Link