Title Information
Title
Cybersecurity Strategies and Policies in Managing 3rd Party Vendor Risks: A case for a quantitative Cybersecurity Scoring and Continuous Monitoring in the Financial Services industry
Abstract
The questionnaire-based assessments of vendors’ cybersecurity posture have proven to be inefficient and ineffective. This single-point-in-time assessment does not capture fully and continuously the cybersecurity risks of vendors. This paper makes the case for a quantitative Cybersecurity Scoring and Continuous Monitoring of 3rd party vendors’ technology infrastructure in the Financial Services industry. To achieve this goal, financial institutions must leverage not only the newly created alliances within their industry but also thoroughly research the methods and techniques being deployed by the early cybersecurity scoring solutions on the market today. The particularity of the proposed scoring model in this report will be to capture and map the financial regulations into its build, which none of the early adopters in the cybersecurity scoring solutions is currently offering.
Name
Name Part
Tanieu, Severin
Role
Role Term (marcrelator) (authorityURI="http://id.loc.gov/vocabulary/relators", valueURI="http://id.loc.gov/vocabulary/relators/cre")
Creator
Name: Personal
Name Part
Palazzi, Bernado
Role
Role Term: Text
Advisor
Name: Corporate
Name Part
Brown University. School of Professional Studies. Department of Computer Science
Role
Role Term: Text
Sponsor
Origin Information
Copyright Date
2019
Physical Description
Extent
18 p.
digitalOrigin
born digital
Note: Capstone
Capstone (EMCS)--Brown University, 2019
Subject (fast) (authorityURI="http://id.worldcat.org/fast/872484", valueURI="http://id.worldcat.org/fast/1033711")
Topic
Computer security
Subject (Local)
Topic
Cyber security frameworks
Subject (Local)
Topic
Security risk vector
Subject (Local)
Topic
SSAE 16
Subject (Local)
Topic
SOC 2
Subject (Local)
Topic
ISO 27001/2
Subject (Local)
Topic
NIST Cybersecurity framework
Subject (Local)
Topic
Vendor assessment
Subject (Local)
Topic
Security rating
Subject (Local)
Topic
Vendor lifecycle
Subject (Local)
Topic
CyberScore
Subject (Local)
Topic
23 NYCYRR500
Subject (Local)
Topic
OCC
Subject (Local)
Topic
FFIEC
Subject (Local)
Topic
General Data Protection Regulation (GDPR)
Type of Resource
text
Genre
Critical Challenge Project
Access Condition: rights statement (href="http://rightsstatements.org/vocab/InC/1.0/")
In Copyright
Access Condition: restriction on access
All rights reserved. Collection is open for research.
Language
Language Term (ISO639-2B)
English
Record Information
Record Content Source (marcorg)
RPB
Record Creation Date (encoding="iso8601")
20100429
Identifier: DOI
10.26300/sypv-n617