Managing Your Vendors and Ongoing Monitoring
To finish off the chapter, we will cover the ongoing activities needed as part of your cybersecurity Vendor Risk Management program. We briefly reviewed this within the review process:
- Step 8 (Ongoing monitoring and annual review): Once the vendor has been onboarded, you will need to ensure they are receiving the correct ongoing monitoring detections. This will include the need to monitor for any breaches with the vendor, whether their score changes within the cybersecurity grading system, if any of the provided services and scope changes, etc. In addition, you will want to ensure an annual review is carried out for your Important vendors to ensure any certifications or anything that expires is current.
It is important to note that even when a vendor is onboard, our job is far from complete. There must be continuous monitoring and ongoing review and check-ins with the vendors, especially the Important vendors. The great...