Upstream and downstream third parties
Often, when we think of third parties, we only think about the vendors providing services to us. However, there is another set of third parties that are equally if not more important than the vendors – our customers. I am not sure whether this is a term that is used in the industry to describe customers, but for the sake of this chapter, we will consider downstream third parties as vendors providing services to us and upstream third parties as customers to whom we provide services.
While we assess our vendors and perform due diligence, our customers must perform the same due diligence on us. Therefore, it is important to ensure that the organization maintains a robust internal risk management and cybersecurity program.
One of the best ways to streamline all the components of a risk management program to satisfy third-party requirements is to conduct an external certification such as ISO 27001 or HITRUST CSF or perform an independent...