Vendor Management

Robinson+Cole Data Privacy + Security Insider
Contact

A challenging risk management project that many clients are addressing is vendor management. Ever since the Target breach, when an HVAC vendor’s employee clicked on a phishing email that allowed an intruder to compromise Target’s system, vendor management has been an issue to be addressed by company data privacy and security teams.

Vendor management is challenging because not all vendors present the same risk to the organization. For instance, the office furniture vendor would not be on the top of the list of risky vendors when determining management of data privacy and security risks.

Just like data mapping and classification to identify high risk data in the organization first, finding and classifying the highest risk vendors first is where to start. That is called vendor mapping. The vendors that are the highest risk to an organization are those that have access to the highest risk data, such as human resources and benefits data, customer data, intellectual property data, financial data and health data. The vendors that have access to this data either directly through direct access to the organization’s system, or that the data is disclosed to the vendor from the organization electronically or through paper records are mapped first.

Once the vendors with access to the highest risk data are mapped, many companies review the data privacy and security measures that those companies have in place through questionnaires to determine whether the measures are sufficient for access to the company’s highest risk data. If the company wishes to use the vendor for services going forward, many state laws and regulations require that if personal information is accessed by or disclosed to the vendor, that a specific contractual measure must be in place with the vendor to have adequate security measures in place to protect it, so privacy and security language in contracts with the vendors are important for risk management and for compliance.

A helpful tip in mapping vendors for vendor management is to work with the finance team to capture which vendors are in the company’s accounts payable records, which can assist in quickly identifying the ones that are highest risk, such as (this is not an exhaustive list) information technology vendors, records management and shredding companies, payroll, benefits, accounting, legal, audit, and other professional services.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide