Загрузка...

Third Party Risk is Really About Access Controls

Third-party risk management often treats vendors like a mysterious external threat while internal access gets far more trust than it deserves.

In this video, I talk about vendor risk, SOC 2, access control, production access, cloud dependencies, open-source packages, CI/CD actions, and why “internal” does not automatically mean controlled.

The better model is dependency risk: what business process depends on it, what data or access does it touch, how should it be scoped, can it be isolated, what monitoring exists, and what evidence is actually useful based on the blast radius?

Third-party risk is real. But the category matters less than the access path.

Видео Third Party Risk is Really About Access Controls канала This is GRC
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять