Home / Current Issue / Paper 1711307
Cybersecurity Perspective on Third Party Risk Management
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
Over the past several years, the growing use of third- party vendors, contractors, and cloud service providers has expanded the possible innovative solutions but has also introduced increased cyber risk. Organizations now find themselves tasked with protecting sensitive data and digital assets that may fall outside their direct control, as many cyber threats leverage weaknesses across third-party ecosystems. This discussion presents a full cybersecurity lens into third-party risk management by assessing the risks associated with vendor and contractor relationships, risk assessments, risk management, and methodologies to measure risk remediation. The impact of emerging attacks and exposure to supply chain and vendor vulnerabilities is considered through the analysis of historical breaches and weaknesses. Lastly, approaches like NIST, ISO 27001, and Zero Trust Architecture are explored for implementation in third-party management, as well as potential limitations of a conventional security posture. The discussion will conclude with the introduction of a proposed hybrid model that applies a combination of risk assessment, contract-required controls, ongoing monitoring, and governance functions that can improve organizational resiliency. Through a proactive and structured approach to third-party cybersecurity, organizations can limit exposure to risk, assure compliance, and develop better levels of trust with one another in today's complex interconnected digital economy.
References
[1] Third-Party Risk Management (TPRM) is crucial because external vendors and service providers significantly increase an organization's attack surface, creating potential entry points for cyberattacks and data breaches. Key references and concepts include the NIST Risk Management Framework (NIST 800-37) for a structured approach, NIST 800-53 for specific control requirements, and various vendor assessment programs that emphasize continuous monitoring, thorough due diligence, and the implementation of stringent controls like multi-factor authentication (MFA) to protect sensitive data and ensure operational resilience.
[2] It involves identifying and mitigating risks posed by third-party vendors and service providers who have access to an organization's data or systems. Key aspects include conducting thorough due diligence, implementing robust security controls, continuous monitoring of third-party security postures, establishing clear contractual obligations, and ensuring ongoing compliance with data protection regulations like GDPR and other frameworks such as NIST. ensuring ongoing compliance with data protection regulations like GDPR and other frameworks such as NIST.
How to cite this paper
@article{1711307,
author = {Ghousiya Begum, Zoya Khanum},
title = {Cybersecurity Perspective on Third Party Risk Management},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {4},
pages = {725-728},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1711307.pdf},
abstract = {Over the past several years, the growing use of third- party vendors, contractors, and cloud service providers has expanded the possible innovative solutions but has also introduced increased cyber risk. Organizations now find themselves tasked with protecting sensitive data and digital assets that may fall outside their direct control, as many cyber threats leverage weaknesses across third-party ecosystems. This discussion presents a full cybersecurity lens into third-party risk management by assessing the risks associated with vendor and contractor relationships, risk assessments, risk management, and methodologies to measure risk remediation. The impact of emerging attacks and exposure to supply chain and vendor vulnerabilities is considered through the analysis of historical breaches and weaknesses. Lastly, approaches like NIST, ISO 27001, and Zero Trust Architecture are explored for implementation in third-party management, as well as potential limitations of a conventional security posture. The discussion will conclude with the introduction of a proposed hybrid model that applies a combination of risk assessment, contract-required controls, ongoing monitoring, and governance functions that can improve organizational resiliency. Through a proactive and structured approach to third-party cybersecurity, organizations can limit exposure to risk, assure compliance, and develop better levels of trust with one another in today's complex interconnected digital economy.},
month = {October},
}