logo

NJP

Tips for Strengthening your Third-Party Risk Management

Import · Oct 18, 2023 · video

so it's just after uh the hour and we'll get started and kick this off so we're here today for live on service now Community webinar with tips for strengthening your thirdparty risk management program we're here with irm authority and we're delighted to have you here as our guest and one of our key Partners in Risk so just before we get started we do have to go over the safe harbor statements um we obviously as service now we're a publicly traded company so Karina if you could just advance to the next slide fantastic um if we do um share any forward-looking details we like to be as transparent as possible in these webinars and answer as many questions as we can if there's anything that's road map related um that may be uh forward-looking and we do uh hold it to our own that we have unknown risks and uncertainties and factors that could cause for changing results but um we'll definitely answer as much as we can and be as TR transparent as possible uh so for the next slide um if we if you'd like to use that QR code that is an easy way for you to sign up for more webinars and meetups in our community um there's I'll share a link in the chat later when I'm done talking um but we'd love to have you come and join as many webinars as possible participate as much as possible ask questions and make this as interactive as we can so we try to uh provide these on a regular basis and that's the best link to sign up and as I said I'll share at the um URL in the chat later couple more housekeeping issues um we do ask that you put your questions in the Q&A as I've as I've mentioned um because we do save that for future topics and interest um but it's a lot better than uh putting in the chat because that doesn't get maintained um but definitely put those in and we will save time for Q&A at the end the presentation is also going to be recorded and saved in the community so if you need to reference something or if you need to jump off if we get a little bit long uh by all means you can come back and we'll put that up there as soon as the recording is available and after the event when you close out you will be asked to complete a short survey and again we use this for informing ourselves as we develop these programs moving forward so we'd really appreciate your feedback so just before we get started I'd really like to uh welcome Karina and harage for joining us today um on our webinar Karina is a senior it executive with an extensive background in helping companies mature their Governor's posture and health she's a forward-looking and Innovative adviser who Blends technology with business and keeps your key areas in mind and she advises companies across through risk programs Karina brings many years of experience both working in the industry as well in her is running her own Consulting business for nearly a decade advising clients on their own compliance security and governance postures and I was delighted to meet her last week at our service now risk event in California so welcome Karina thank you and Karina is joined today by hares kandola sorry about that um hares compliments Karina's business savvy with extensive Enterprise platform technology experience he brings Decades of experience as well but more on the technology side in successfully delivering solutions to address the Strategic business goals as the chief technology officer for irm Authority he is responsible for setting the overall strategy for technology implementation and best practices he also has deep service now experience having worked across the platform as a subject matter expert for itsm security Ops irm working in program management business processes and performance analytics so welcomed you both today to the webinar and I'll pass this over to you Karina if you'd like to well uh introduce yourself and uh start the uh really really indepth uh presentation for today thank you all right uh appreciate everyone joining us today really a lot um it's early in the morning for some of you so uh wanted to kind of quickly go over this and give a few asterisk items here the first aspects item I think is terminology um so right we're kind of evolving this uh piece of the platform um so there may be some interchangeable words here some uh third party risk management some vendor management uh whatever you call it in your company service now says yes uh you can call it whatever you like to right and it's all okay because really uh the platform is scalable enough enough to handle all of that I in my presentation may use words interchangeably so uh just kind of a caveat that uh we tried to keep it consistent but uh different companies call it different things so it's fine if there's a slip um the other thing is we kind of broke out the whole life cycle into four sections we're going to go into some uh really things that we hear over and over again about um things that you ought to include in your question s uh and so we're going to put a little bit more focus on that but unlike our prior webinar we're going to put more time into the demo so I'm going to try to talk fast but not too fast although I do talk fast uh so we'll try to um I I'll try to be as clear as possible and I am going to go ahead and take myself off for the for camera for the rest of this so we can pay attention to all the great animation here that's going to be happening on the screen all right so I'm I'm going to go a little bit bold here folks and I'm going to really start with um your governance right um the governance of your company uh really needs to be dictated by your irm right your integrated risk management your GRC programs where you have those published governance documents whether they're you know it says policy here at the bottom but inside service now that's the table name right but these are your processes your standards your procedures your templates your whatever is the thing that provides guidance to the people running the vendor management the thirdparty risk management program right it really starts at that governance level and you need to make sure that those documents are providing the right amount of information to um to make make sure that this program is continuous and flows because you're going to take those control objectives and you're going to actually attest against them and show how well you're doing to the Auditors and Gathering that evidence so we're going to get into that in a minute we've broken this out into four sections first one really is that identification kind of that calibration of you know who's the vendor why am I here why am I doing this uh doing that identification second one is kind of what questionnaire does that vendor get uh you know I don't want to send out you know more and more questions I want to send the vendor the right questionnaire in the beginning and there may be different questionnaires based on what that vendor is doing for me right I want to make sure that I'm carefully taking a look at the replies that I'm getting back from that vendor and then of course I want to make sure that I'm understanding that vendor long term you know what are they doing for me again uh you could call this operational monitoring you can call it continual monitoring you can call it you know continual Improvement you can call it really whatever you want to you may see something on TV that says oh well this this third party went and had a breach well you may you may want to trigger off an assessment uh that might be one of your conditions so we're going to be talking about that as well so let's start with the first piece over here on the top right hand side right so let's talk about identification this is the thing that really kicks off this process so again I'm going to start every single one of these because the guidance that we're going to get is out of our published documents right it's it's saying to us you know we have to adhere to this regulation and this framework and uh the example we're going to use in our demo is Hippa which actually requires a baa right there's two citations in Hippa that says you have to bet your vendors right you have to have a contractual contractual obligation signed so you have this governance oversight you're going to have your control objectives and then you're going to have those triggers defined um you know maybe you're getting a new service and you want to have your uh legal department start kind of you know asking you to do an assessment uh maybe you have an existing vendor already in place but they're not meeting their slas uh maybe you know maybe you're thinking about moving away from that that third party and you're saying uh you know I I want to start looking for a replacement uh maybe six months before the contract's expiring so that I can figure out if they could do a little bit better for me uh before I go into the next contract cycle uh so you you definitely want to control uh how how much ability you have to to to to actually um to you know you you have the control of of of of of this so your goal is uh basically proceeding with the third party based on what's happened so sending questions um this is pretty important right so again your governing document is going to tell you you have your vendor identified you're going to know what third party receives which questionnaire uh this is really really important you need to define the parameters for the timing the goal for this section is really to make sure that the right question the right questions get sent and uh this is the part we kind of want to hone in on especially with all of uh kind of the security considerations that are honing in on uh and and kind of introducing this concept of third party and fourth party right so uh you have your company your company has data right we know this potentially some of your data is sitting at a vendors and so some of the considerations you need to ask about in your questionnaire is of course some of the basic stuff right um you know if especially if your data is stored transported or processed uh you know you need to make sure that you're understanding at that vendor location how many people have access to that data that your data uh at a at a at a heightened privileged level right um how often are they purging your data have you provided them data classification and and destruction guidelines um right what you know what are your insurance Provisions should they uh lose some of your data you know breach notifications are actually really important because um some contracts actually that I personally have read say we we don't have to notify you of a breach unless six months goes by right gdpr says 72 hours so you have to make sure that you're going to make sure to uh carefully uh ask these questions as part of your questionnaires uh the the last bullet here is pretty important right so data at another vendor so if if we go along the diagram at the top the data at a vendors uh imagine now if you're vendor when and uh of course they have data right but they took some of their data and they sent it to their vendors what if your data is involved in that pass right so unfortunately what we're seeing right now is this is Perpetual um you need to be really careful and ask how many passes uh is your uh data being moved Downstream uh you you need to you know call your insurance company and say you know if my vendor is passing on my data to their vendor how much control do I really have and you let to understand those Downstream controls all the way down they don't have the same uh you know due diligence of physical logical controls as we do W with our in our own space you you can't really vouch for that stuff so you have to be very careful and ask these very very specific questions so the one more other consideration for the people who ask for sock as part of their vendor vetting um kind of process so uh please when you receive those sockos do a control F and look for the word subservice organization please because many many sock twos do not include subservice organizations this is very very very important when your vendor sends you a sock 2 you think okay they're good um that sock 2 basically will most of the time from what I've seen will say doesn't include subservice organizations which means that there's an assumption with that sock too it basically says there's an active thirdparty risk management process that's already in place you've got compensating controls and anything compensating is covered in a contract with your client so so please be very careful to to do that checkbox sock CHS are great I'm not saying anything bad about sock twos I'm just saying that don't assume that just because someone sends you a sock 2 that there's Downstream controls that are in place socks just exclude them a lot of the time right so please understand those limitations as you're looking forward all right um and then those limitations of course look for those excluded areas in the in the the sock toos and and look at your own contracts and agreements and then you know your guidelines every company is different so it's it's really up to you for for your uh guidelines okay so uh we're we're you know we're we're coming up here to the top we're we received our we received the documents back right we send out we know who we send it to we sent the questionnaires out uh they sent us back information again we're going to go back to those published documents ments right in our irm uh we have we have a policy that has control objectives that says okay you've got published doc okay this is insufficient here's when you escalate um you know here's he this this answer over here we we accept it here's an exception uh you know oh well this is kind of a fuzzy answer let's go down the fourth party path and the fifth party path and start asking about the vendors vendor vendor vendors uh pass of our data right these are things we want to ask so um and then how do we open an issue so any of those things that we don't like that we want to track long term uh we all need instructions uh on this so our goal for this section really is we've got those questionnaires back and now they're completed okay so now we have our things done we're in operational kind of study state right so so um we we we've assessed our vendor we've received the questionnaires now we need to know who you know when do we do this again do we do this again like do we do it every year do we do it every two years do we do it when something happens do we do it when we see a breach on TV um do we do it when a contract is up or legal calls us do we do it when an SLA is breached and they're not meeting their their you know contractual oblig ations for us so we really need to make sure to in our documents that provide guidance for how this program works in irm we need to provide instructions on how really this uh this works long term for us so goal of this section long-term active measurement and monitoring and so with that okay good so on the demo side where we're going to start is one of the first things that Karina said here is um your thirdparty risk program has to be aligned to your your governance and those regulations and she called out Hippa so let's start with HIPPA and we'll kind of take a look at those Authority documents first so under favorites I'm going to go ahead and go to our Authority documents so in our in our system here we have a few different Authority documents um Hippa let's go ahead and take a look at Hippa here so I think the key thing is really you want to have the whatever regulations whatever you have you want to have those captured and connected to your thirdparty risk program somehow so let's go ahead and take a look at some of this language here and see we happen to be doing it here in service now but it doesn't have to be in service now you can have it in any tool that you have it so we've got the hipper regulation here and if I scroll down we just have a very very narrow subset so we have two citations here and uh I'll go ahead and click on the first one and for those that aren't aware the citations and service now are pretty much word for word depending on the version um these aren't edited at your company these aren't changed at all these come directly um from whatever entity is doing the regulation or the Govern and so forth um so this one here is uh business Associated agreement baa requirements so there's requirements here for baa um some of what is mentioned there's got to be appropriate safeguards when handing Phi or E Phi data um it helps to ensure the business associates are held to the same standards of privacy and security as covered entities so here we have one of these and oh sorry one thing I forgot to mention so we're doing this on the latest release of service now so this is Vancouver um the Vancouver release and some folks may be on um the vendor management the vrm product some may be on the newer thirdparty risk management product um everything in vrm is still valid in third party risk management there's some slight changes and so forth but just wanted I forgot I just wanted to set that context as we go through this so here we have one of those citations for baa requirements and if I scroll down here we'll see the control objective so there's an actual control objective um they're also I refer to them also as policy statements so we have a control objective here this is mandatory baa completion right so control objectives and service now relate to your policies and your policy statements so it's really important that um these get connected together so I'm going to go ahead and click on this control objective here and let's kind of take a look at this for just one moment so here this is unlike the citation which you don't edit that comes directly from the authority this would be the specific control that relates up to your policy so for this one for our fictitious company here um it says according to third party risk management policy all vendors who interact with Phi or Epi must undergo a b baa assessment and have assigned baa on file as long as they are providing services to our organization it says it right there and um that's that's part that's one of the controls they're monitoring against so I'll go ahead and scroll down here and we can see a few different things we can see under policies there's a thirdparty risk management policy connected to this we can see some controls and the other thing that we can see here is assessment metrics so some of you may not be familiar and might wonder what are assessment metrics so I'll go ahead and click here and what we have is in service now there's a connection between the controls in your your risk management your policy side of the house that actually connect to your third party the third party risk module so these are just some of the metrics that are being captured specifically for baa so I'll walk through a few of these so all of these have baa qualification so what what you're going to see a little bit later is the questionnaire and the assessment that goes out to the vendors um the example we choose is specifically around ba for Hippa here but you can see the actual questions that we're asking them right so I'll I'll go through a few of these we didn't we didn't enter the whole baa questionnaire we kind of picked a subset just for this demo to kind of get the idea what's happening so some of the questions that are going to be asked you carry cyber insurance if so please include your certificate and then you for those that are technical you can see the data types here as well and some of the other technical information so do you have a contract uh or a master service agreement with our company yes or no and then this one right here do you have a definition for Phi or eepi information so these are some of the questions we'll have another view sorry we'll have another view as we continue so we can really focus on the questionnaire but really the questions you ask and connecting those in the right places within a tool and this case so that you can get visibility on those at a higher level that's really one of the key things that's going to strengthen your third-party risk management um process so I'll go ahead and click on policies and now let's go ahead and take a look at the policy so here can I just drop you for one second um someone we asked is um the questions that you're talking about the uh these are questions in the tprm questionnaires being mapped to control objectives in the irm solution is that correct yes ma'am yep they that's absolutely what it is correct clarify that and also where are you getting the content for Authority documents uh great question Karina do you want to take that one where we got our Authority document Hippa um information or we can get back to that after the demo that's fine okay okay let okay sure we can get back to that one uh yeah good questions uh yeah and Brazen feel free to stop me when I'm on something because I I can't see the questions as I'm going this all right thanks so for our policy here um the policy application service now we're just going to focus in on the third party uh risk management policy so uh I would assume most of you are familiar maybe some of you aren't um the Persona we're using is John tprm manager so John is the tprm manager um they own um the third party risk management policy and I won't go through too many details but essentially you can see the policies here in service now kind of go through the different sections and so forth um some Pi related information and this policy is specific to our company right so some other General best practices is um your policies should you shouldn't have a separate policy based on different regulations you should have one third party risk management policy that encapsulates everything and keeps getting improved and updated um over time and so forth so the last thing here I will show you at the bottom under control objectives we only put three on here just to get the idea but essentially we have that mandatory baa completion which is one of the controls will be monitoring and it's in the category of third party and supply chain oversight and there's there's two others here so this one here is all third parties engaged with us must undergo assessment and have a signed contract in place um that's also connected to Hippa and this last one here detailed the number of people at the third party that have privileged access that's also a good one right we there's a lot of data and security policies around page access um that happen across the board so there's there's a control we have in place for that that we would want to monitor as well um okay I think that covers there's so much to talk about here but I think that covers what I want to go out go over on kind of the policy and compliance side and how that links to it so at this point I'm going to have go ahead and go to the vendor and thirdparty risk management workspace and we can kind of take a look at how we would see some of these things over there can you also address how you're bringing the questions in from tprm that was another question that came up uh how how we're bringing them in uh sure sure sure sure I'll I'll includ I'll include that as I go through it at the right Point fantastic yeah so as far as personas go we're we're going to be John the third party risk manager the other personas that use this is going to be the assessor and the reviewer um depending on what role they have in so Bush so um since we have different levels of um I guess understanding I'm going to go through a really quick overview of just this kind of module so on the home screen we have third parties and engagements assessments can be done specifically on a third party or it can be done through an engagement and if you do it on engagement it's kind of a specific scope as in you're scoping out a specific area in that engagement we have some of that information we can see top risk areas here security environmental and so forth so this is really the overall page um where the third-party risk manager would look at things here um I won't dive too much into due diligence due diligence is um um kind of a newer feature and thirdparty risk there's there was an a webinar in August um from the product owner that um kind of talked about this really well but there's due diligence requests that can go out then you have your risk activities let's go and let this load um this is more of kind of management as you go through it um then there's a map that's going to connect to where your third parties are just if you want a visual gra represent ation and then tasks so the task screen here is this is typically for the assessors and the reviewers for those types of personas they'll have their tasks and it it typically can be tasks working with different vendors uh or suppliers as they have um tasks that need to occur and also issues that come in with the issue management right A lot of the time either a question isn't answered correctly or there's not enough information and there needs to be some followup and some back and forth and the last one here is the list and then on the list we can see um just all the different applications and so forth so the example we'll use under all third parties we're going to use this sample uh this sample vendor called medical device vendor right so we'll go ahead and click on this and we have our medical device vendor here so we've got some information about the vendor what their strategic partner of ours now in this situation um they've already been onboarded as one of our vendors and they've already gone through their onboarding process um but there's some other assessments that have happened so if I click on more we can kind of take a picture and see what's happened what hasn't happened so a few other logistics here I'll click on third party contacts so under third party count contact we just have Monica Turner here as our primary contact so third party contacts you you need to have at least one that's a primary contact here and these are going to be on the vendor side who are you engaging with you need at least one person there they can add other vendors they and they can support you um within the system on that side so this is the vendor side and at the top the vendor management that's going to be on our side as the company on the company side of this um if I look under more here I can see there's two assessments so I'll go ahead and click on assessment here so there's two assessments that's happened um we can see one is closed which is a security assessment so there's a security assessment that's already been done and there's a baa qualification risk assessment for thirdparty medical device company that's in the gener generating observations so let's go ahead and click on this and kind of look at this assessment and kind of find out more information about it um so I'll answer the question one of the questions asked is how do we generate those so um your your as far as your assessments on the technical side right you configure them in the tool right you can use a third party you can even write out your questions in Excel and you can import them so there's def definitely a few different ways you can come up with your specific questionnaires or you know like irm Authority and other companies like us we we have these that we do for our customers where we'll help them craft them um so there's a lot of different sources on how you can put them together um it's a little out of scope for today to show the configuration of how that's done within the tool um but that that would be part of the setup as well so I I hope that covers the question that we had there uh any Rosa any other questions come in related to this I think a couple of questions are around Authority documents and authoritative sources so um I think that might be Karina if you might yeah I'm sorry I had run for coffee I really apologize at that moment um so I I download this from HHS Straight From the Source any any regulation I always go straight to the source so so the Hippa is always downloaded from HHS thank you okay thanks and one of the other questions that came in is uh can you give some recommendations on how to come up with good quality vendor assessment questions which I think you addressed that in that there's um you know irm Authority can consult with folks on their questionnaires and and give guidance there and then with the most recent version of the product there are a lot of uh what I would say is starter templates for a variety of regulations in the product so there's a whole host of uh depending on location and or uh industry and or regulations that you need to deal with there are a lot there's a lot of content in product now um to get people started but I would absolutely advise that you consult with someone or determine with your legal department the appropriate questionnaires and wording um because it's the questions are critical right yeah absolutely okay so continuing on we have our ba qualification assessment here so let's kind of take a look and dive into this one so we have the different um States across the board first it was submitted to the third party um a response was received and we've actually looked at that response and now for this one we're in the um generating observations so we can see that there was a a risk rating of four which is a low score that was given to this and we can see here there's a questionnaire the ba qualification and there's a document request for sock so part of part of the questionnaire is um we asked for docu what what documents do we need and what are the specific questions so there's a few different ways you can set this up it my recommendation and I think ours is if you have specific documents you need every time do them as a document request request those those documents in the system and you can get those all added to Sur now through document requests um I'll talk through there's another way you can do it which I'll talk through in just a moment so this one's 80% completed I'll go ahead and click on this questionnaire and let's take a look at this from a different view so now that we looked and this has been received let's take a look from the thirdparty risk reviewer so when I click on this it'll go ahead and open the questionnaire can you see my screen with the questionnaire open yes okay perfect so this is the thirdparty risk reviewer view so as the reviewer I can see I can add my review comments and I can look at the notes and comments to see the history if there's anything in there now I'll scroll through the questions and there for this one there were a few issues it looks as we go through it so one of the questions was do you have a contract terms and conditions or mass service agreement with our company they said yes and then we asked them please specify Who provided signature and the fully executed date they just wrote CFO that's it they didn't give us anything else so one of the things the reviewer can do is this is a box for them um they can check this include this question when creating an issue um it's not checked because an issue as we can see with the word issue here an issue was already created so it's been done so for each question you can include internal comments for your third party risk and for your company to see if you have comments on what they're doing as you're talking to your vendors um you can kind of put in some of the internal comments these are particularly useful when you're looking back a lot of the time there's a story of you know maybe somebody's new there's a new um somebody got promoted and you're new to the department or something like that and you don't have the history and you've been using the tool for a while so particularly finding out and using those internal comments and sections here really tells the story in the system so it's not siloed and through emails so that's really something that helps a lot is keeping everything in the tool here so you've got your internal comments and then comments for third party this is what's going to be sent directly in this case it's Monica Turner it's going to be the comment that's sent directly to the primary contact on the vendor side so please provide a name of the person the CFO is not good enough you can provide details as you ask down here it says do you sign an NDA with each company that you work with they said no and then we internal comment we need more information from these folks and then the comments for third party it says please explain right and we've this this has been linked so one other thing that some people aren't aware of you can have multiple questions in your assessment collected together in your issues for issue management so when you want followup or you don't like the responses or you need more help um issue an issue will get created in service now to kind of capture that and you can group the questions together uh the next one here is do you audit do you have an audit firm yes please provide the frequency they do so and then for this question here do you carry cyber Insurance please include a Certificate of Insurance detailing cyber cage included there's an attachment icon here and it says if no please specify why why so this is um you can do document requests but if you have more of um an explanation than a document request sometimes you can ask for attachments in the questionnaire so depending on what you're asking for for your vendor or you want information sometimes depends on the specific use case using document requests are great um it's a great way to track things I sometimes like to include some of the questions for attach m in the questionnaire itself so it kind of depends on what you're asking for and your relationship with your kind of your experience with different vendors for that as well uh we'll scroll down and then the last question here do you have a definition of Phi Phi um yeah and this is this is a great question anything hippo related to ask this question especially since yes there are very clear definitions of what this is but not everyone has a clear understanding of that so it's good to be on the same page to make sure your expectations are being met on the on the vendor site as well like we have it here um so we have that information here and we give them a chance to give us an explanation of what they're asking for and then we can also include any comments to them if I check this comments for third party I can include a comment to them as well and ask them any questions for this uh okay let's see R any questions on this before I move on there was a note that someone needed to add an additional field for um questions each question for responses and um they also noted that um if they look at the questionnaire to see the additional questions then they have to navigate to notes is that correct yeah so they're talking about the configuration so right here I so this is a question so when you set up the questionnaire you'll ask a question such as this and then there's um in the configuration there's something called uh additional information that's you can actually rename the additional information which is what we did here so this so the additional information we renamed that part of the setup to whatever you want so instead of asking for additional information you can modify that for what you're specifically asking for um so that was just a configuration change that you made to make it simpler for the yeah it's it's actually a great one so instead of asking so you can say here's your question provide additional info you can actually modify the additional information when you're configuring your questionnaire to ask something relevant for your specific question and then it'll show up here so it does it does show up on the notes that is correct but that's not the only place it shows up it'll show up with the specific question here and um some of that information can be captured in the notes if you have a back and forth so the additional information every question when we have a follow-up section uh like here provide frequency details this I mod we modified the additional information to ask specific questions to get better data from our vendors as we go through this I I hope that was relevant to what they were saying I think so but I think they might need a little bit more help afterwards so we'll follow up after the call okay sounds great all right so now let's go back to our other screen here so that was kind of diving deeper into the baa questionnaire this one's 80% um you can make all the questions mandatory we did not just to show you that they don't have to be mandatory so 80% is fine for our example here um if you have too many questions or I think this is a subset our original questionnaire that we pulled from had almost 100 questions in it so it's a very very in-depth questionnaire that we had um some other things I wanted to show I'll click on details here um the notes Here For Work notes and comments here this is connected to the questionnaire as well so as they ask questions and so forth the the work notes will be connected um the work notes are connected to the question questions within um the Vendor Portal and the views for when the vendor actually enters an information and provides it to us some other things I wanted to kind of talk about here um rep repeat assessment here so um one of the things Karina also mentioned is triggers and I think there was a question early on about triggers um so this is all based on the configurations for how you set this up so based on the type of um based on the type of partner um relationship if it's a strategic partner supplier depending on that relationship you'll have specific questionnaires um organized based on that relationship and the other side is you can set how often do you want this to reoccur so the first use case is you know you'll have you'll set your standards within your policy we assess our vendors annually something like that so you can have you can have a general statement around how often you assess vendors and then um onp specific uh these can also be connected to specific due dates and triggers so I think the exact question is we had a document that was expiring can we reassess them how can we handle that um yeah you can configure it in the tool to reassess based on specific dates for when the document expires um when an engagement ends when a new engagement is beginning um you can set up engagements to automatically be created as well it's a combination of a few things configuring the tool with automation setting up your policies in place to do to have kind of General standards across the board and some of it's also going to be at hoc right it may things may change from time to time and you may uh it's out of scope for this demo but the demo I'll referen back in August that the product owner for third party risk went through went into details of how in the employee Center you can do ad hoc demos which were very good so sorry ad hoc requests for modifications so if you're offboarding to vendor if you need to reassess a vendor you can also do those ad hoc and there's a great process for that as well uh I'll pause there and see any any other questions I think some of the other questions were about the the portal which I think you might have been going to show there's uh there's two so there's two portals there's the employee Center there's the employee Center portal and then there's the Vendor Portal so vendors will have a separate portal that they can log in they can log into um I thought it'd be best to let's see those two aren't in scope for this demo but um let's see uh I'm not sure if I'll be able to connect it here I can take I can take a look and see maybe when we go to the Q&A portion because I don't have it set up but I can I can set that up when we kind of go to General General Q&A let's go back to that and I I think I'll be able to touch upon that as well great um can you expand on some of the recommendations of around breach notifications yeah absolutely um I think Karina you do want to start off on the breach notifications and I think I'll I'll set the stage because I think there's two different types of breaches depending on how you whether it's public or not right so a great example is you see something on the news that so and so company had a breach what do you do or maybe it's not public so Karina do you want to talk about that a little bit and what some recommendations are yeah so I think from a you running your operations and running your company perspective um so for instance I have very Dee rooted kind of roots in security right so I get notices several times a day of leaks and breaches and you know somebody's lost data so I'm always looking for data centers in those notifications because all I'm thinking of is which one of my clients has one of those data centers listed as a vendor when they did their assessment right and and who do I need to call to notify them and say hey warning warning um go find that contract that you have with that vendor that says this is when they notify you of a breach the unfortunate thing is a lot of times when we pull up a contract um the contract says well we're going to notify you of a breach within six months maybe if we feel like it if we feel like maybe you're involved but we're going to figure out a way to not have you be involved so so these are really important kind of elements that you want to go through inside your own company to determine how quickly is your thirdparty uh vendor or or whoever is providing any sort of contractual obligations to you contractually how fast do they have to notify you that they may have lost your data that they've discovered a leak that they have a security violation remember folks Securities Exchange Commission right has on July 26 has now required that um you know material weakness cyber security breaches be disclosed within four business days four business days so those contracts that we have sitting on our Shelf versus what may get filed with the Securities Exchange Comm Mission 8K for those data centers and those companies that house your data there may be a discrepancy there so this is something we want to get our arms around definitely that's that's the non um platform specific answer yeah I guess I beyond breaches um is there a Best practice or what are the most common triggers to send out reassessments and what's the frequency of that I think this ties into this conversation I would say as soon as you see it on on as soon as you get a notification that someone's been breached send them an assessment yeah so two things that that's true the other thing I do want to mention is uh let me show you here when setting up your data in the system there's um there's something called thirdparty risk areas so specifying and using your your risk areas and connecting those to your vendors helps organize your data so you can kind of basically know which vendors you want to contact sure you'll definitely know some of the key things if there's a specific company but if there's security thirdparty risk areas like security risk or data risk if you tie that to each one of your specific vendors in here it makes it much easier to automate it right so maybe it happened to one vendor or there was something out there but you want to assess everyone so for our example here it's just compliance risk right so you can specify your thirdparty risk areas in more detail and you can connect those to all your different vendors and third parties and that that'll just make it easier on the tool side so that you can instead of just having to specify these four vendors or five it'll make it easier to categorize things yeah and as we were talking about how people use terms interchangeably um one of the things uh domain is a good another good example of um the risk areas so you want to think about all the risk domains we just call them risk areas within the product um another question um How many types of assessments are there usually uh good question I mean so well I'll start it off and then Karina you can answer I mean out of the box there's it's it's flexible right so out of the box kind of especially with the new Vancouver release they have um with the due diligence you want onboarding right whether you know assessment or whatever you want to call it you have an onboarding questionnaire assessment that you ask them to kind of get them onboarded to set the stage then you have your engagements and it just depends whenever you're engaging in a a different area with a vendor right so let's say um you're working with a Consulting engagement with a company and then you have another engagement with that company where they also are supplier agreement or it's different scope for different areas you you you would want to set up an engagement to assess those various parts uh of that area so and then the other side would be compliance based and then K I'll let you kind of add from there yeah so so really um it's the word risk right so um how risky is that there party for you so is that a is this a vendor who owns all of your golden eggs right he has the most important data your client data your general ledger data your consumer privacy data your Phi pii data right if that is the if that vendor contains all of that information well you may want to have a very diligent set of questions in front of that vendor or third party and then uh for the for the vendor the third party that isn't that that doesn't have all of that information and isn't that critical to your operations well maybe they get a lightweight questionnaire right maybe it's not that important to have them be hounded and have the Cyber insurance policy be sent and show me your perimeter security controls and tell me how many people have privilege logical access to the data on their side right I mean it doesn't it it's really again it goes back to that identification that first point in the presentation where we talked about who is this vendor how important is this vendor to me and what kind of questionnaire do I need to send them right that's where you're doing that risk gauge based on your governance structure can you talk a little bit about frequency of assessment so um a couple of people were asking can we set frequency of audit can we set frequency of assessment um you know can we set it uh every two to three years you know talk a little bit about frequency if you could hertage do you want to take this one you can the short answer is yes yeah sure um it I mean it's a simple one how from the tool side it's however often you set it up annual tends to be the the go-to to set it up annually to do annual audits it it ties into a lot of different things in integrade Risk Management you do audits an annually same with thirdparty risk doing an annual audit with them so um annual is kind of the go-to I think doing it quarterly or something like that it's it's a lot of work I think the other thing you have to understand is you got to be realistic with your vendors so people bid in this space depending on the size of the vendor especially the big vendors it's so hard to get information out of them and to get any kind of relevant and good quality things a lot of them tend to send you the generic packets um so I think you also have to be realistic with what depending on the size of the vendor supplier you're working with with what you're able to get so that's I think something good to consider as well and maybe if you have a lowrisk vendor maybe if they're not that critical for your operations then maybe you want to send it every two years or just send it six months before their 36 Monon contract expires just to see how they're doing and you know check to see if they've met slas and if you have no interest in moving to another vendor just do it one more time before you resign a contract just just to see how they've been performing and you know before you go into an auto renewal for the next three three year and tools side it's flexible right once a year twice a year annually whatever you can you can just configure s not to do anything that way it's it's pretty easy to do I know we're coming up on the hour um can I just ask one more question can you talk a little bit about integrating um some of the vendor data so if vendor data and contracts and things are stored in other systems can you talk a little bit about the integration how that's pulled in or how it's used within service now so I'm only gonna say just pull it all into service now there's really no need to have it everywhere else it's almost um I mean you you know your published policies all need to be in service now uh sure I I mean so look if you have to have it all over the place then at least figure out what those trick triers are right those key areas for the contracts and and and the and the legal things that may have uh you know if your contracts are stored in a different platforms there's always uh kind of triggers that happen date driven contracts uh contractual obligations so at least pull those in at least build your governance program for your third-party risk management in service now and pull those triggers in from HR from legal from Finance all all those things influence and matter for your thirdparty uh program yeah and I would say that we've you know the general answer is we've got open apis that will connect to the systems that you need um and we do have people that you know do use Erp systems for a system of record and we will transport information back and forth and that's also a question um somebody asked about importing and potentially aligning the Sig or Sig light yes you can and we do um provide and use Sig and Sig light in many instances so whether you're using that in it's entirety or using pieces of that um absolutely uh it's it's available and uh provided through service now not as an additional fee thank you everyone for joining us and thank you for your attention yep do you mind just putting up the last slid so we can go through in additional ways they can connect with us if uh needed just there's a few URLs on there that I want to make sure that your information is shared on the question and answer slide great and then if we click through um there's a lot more resources from service now um from our impact uh program to training certifications and um expert services that are available to you and then finally if you're interested specifically in Risk content um there's a lot of different ways that you can connect with us as well in the community signing up for um more events registering for those webinars Andor participating um in our YouTube playlist because we put a lot of content up there to try and educate folks so with that I will say thank you so much guys for the in-depth information I know it was a lot to throw at people please come to us or IR irm Authority with questions um I really learned a lot today being more on the tprm side the irm side myself so thank you for that and um we look forward to seeing you again at future events absolutely you have a great day everybody bye guys bye

View original source

https://www.youtube.com/watch?v=Wu2KGOgk92A