170 likes | 308 Views
Managing Third Party Risk. In a world fraught w/Risk. Trust In the Cloud How are you Protecting Customer Data? February 26, 2014 Case Study Vincent Campitelli – McKesson Corporation. Vendor Management Life Cycle. How are they identified ?. Spend Analysis Corporate Procurement
E N D
Managing Third Party Risk In a world fraught w/Risk Trust In the Cloud How are you Protecting Customer Data? February 26, 2014 Case Study Vincent Campitelli – McKesson Corporation
How are they identified ? • Spend Analysis • Corporate Procurement • IT Procurement • Legal /contracting • Compliance Officers • Business Unit managers
Assess inherent Risk • Service description • Contract Review • R. A. questionnaire • Risk Rating
Conduct Due Diligence Moderate RISK Inherent Risk LOW RISK High RISK • Contract PP P • Security Exhibits P P P • BAA P P P • Validation procedures P P • On-going monitoring PP Residual Risk
Apply Risk Mitigation • Contracts • Company paper • Right to audit • SLA’s • Conditional Acceptance • Third party reports • Annual requirement • Scope adjustment • Corrective Action plans • Corrective action plans
Monitoring • Geopolitical events • Environmental events • Business events • Contract events • SLA performance • Mergers/acquisitions/Ownership • Fines/penalties/violations • Audit failures
“Going to the Cloud” • Lack of visibility • Lack of control • Contractual limitations • Right to audit • SLA limitations • Exit strategy • Data retention/location/return/use • Reliance on 3rd party reporting • New Requirements • Monitoring • Oversight
How are they identified ? • Spend Analysis • Corporate Procurement • IT Procurement • Legal /contracting • Compliance Officers • Business Unit managers • CLOUD BASED
Assess inherent Risk • Service description • Contract Review • R. A. questionnaire • Risk Rating • Tailored for CSP’s : • CSA CAIQ • CCM v3.0 • Star Registry • Response indices • Yes • No • AI
Conduct Due Diligence Moderate RISK Inherent Risk LOW RISK High RISK • Contract PP P • Security Exhibits P P P • BAA P P P • Validation procedures P P • On-going monitoring PP Residual Risk
Apply Risk Mitigation • Contracts • Company paper • Right to audit • SLA’s • Security SLA’s • Conditional Acceptance • Third party reports – SOC 2 • Annual requirement • Scope adjustment • Corrective Action plans • Corrective action plans