Managing third-party security
The complex ecosystem of the industrial internet involves several vendors and suppliers. Multiple products and services in an IIoT deployment may be based on an as-a-service subscription model. An organization's security program must take into account both purchased assets and subscription-based assets. Some third-parties, such as public and hybrid cloud vendors, employ a shared security responsibility model.
Insufficient security measures in third-party practices and infrastructure can expose an organization to threats that it cannot control. The security program must define ways an organization can track external vendors, and control how vendors access and manage an organization's assets. The evaluation criteria ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access