Element 2: Risk Management Process for Third-Party Cyber Risk
Entities have an effective process for managing third-party cyber risks through the entire thirdparty risk management life cycle.
Entities should identify, assess, monitor, and report to the appropriate level of management the
cyber risks associated with their third parties, and manage them using a risk-based approach. They
should adopt policies and control measures in order to protect themselves against contagious thirdparty cyber risks. Entities should understand the cyber risk management practices that critical third
parties use, including risk management practices related to their use of subcontractors.
Identification of Third Parties and Criticality
Entities maintain an inventory of their third parties and an understanding of how these third parties
are critical to their operations.
The inventory should contain: a list of all third parties; the services and functions they perform;
the level of access each third party has to the entity’s systems; and the type, sensitivity, and location
of data maintained or processed by each third party.
Entities should be able to identify the criticality of the third party to the operations of the entity.
The factors that determine criticality can include the degree to which the third party supports and
has access to critical functions and core business lines. Entities are encouraged to further assess
the ICT supply chain associated with their third parties using a risk-based approach. For example,
a key step could be obtaining a software bill of materials from software suppliers, such as a list of
software libraries that comprise the software and which are not strictly related to the relevant thirdparty relationship (e.g. open source).
Cyber Risk Assessment and Due Diligence
Before entering into new third-party relationships and during the lifespan of the engagement,
entities conduct cyber risk assessments and due diligence to consider whether these relationships
are consistent with their cyber strategy.
Entities should assess and manage the potential cyber risks and vulnerabilities that a third party
and the ICT supply chain may introduce to their operating environments, as well as risks associated
with a third party’s ability to deliver its product or service. Entities may consider risk factors such
as: the criticality of the supported business operations, the third party’s level of access (both
physical and logical); sensitivity of the data or system hosted or accessed; and method of
connection.
As part of an entity’s overall due diligence, information gathered may include a review of a third
party’s current cyber risk strategy and prior performance related to cyber resilience. Entities should
conduct due diligence activities pertaining to cyber risks both prior to contractual agreements and
during the lifespan of the third-party engagement on a risk-based approach, to provide
proportionate up-to-date assurance that the third party’s risk management programme is conducted
in accordance with the entities’ control environment, inclusive of legal and regulatory obligations.
Entities may consider the use of common assessments of third parties to gain efficiencies in
conducting risk assessments and due diligence activities identified above.
TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction.
3