Hacking Skills Not Required: Your Vendor Security Programs are not a Secret

Hacking Skills Not Required: Your Vendor Security Programs are not a Secret

The SIG Resource Center is moving to The SIG Community. If you are a SIG Member, or enrolled in SIG University, and don’t have access yet, you can do so here. Already have access? Log in and visit the new SIG Resource Center.

Your organization’s third party risk assessment process has likely come under increased scrutiny. Fortunately, new methods have emerged to help control and manage third party security risks. We will present techniques for measuring the information security quality of any company just by making a simple examination. No hacking. No insider information. No laws broken. The art is in knowing where to look and how to read what you see. We will explore the breadth and depth of security program information captured using this method and describe how it can be done. To provide context, we will include representative analyses of several large organizations.

Topics covered in this session included:

  • How vendors expose their security decisions on the internet
  • How this information can be captured and analyzed
  • What actionable intelligence and conclusions can be gleaned from this information
Contributors:
Categories: ,
SRC Type: ,

Please log in to download the document.

Please log in to view the video.