- Title Information
- Title
- Cybersecurity Strategies and Policies in Managing 3rd Party Vendor Risks: A case for a quantitative Cybersecurity Scoring and Continuous Monitoring in the Financial Services industry
- Abstract
-
The questionnaire-based assessments of vendors’ cybersecurity posture have proven to be inefficient and ineffective. This single-point-in-time assessment does not capture fully and continuously the cybersecurity risks of vendors. This paper makes the case for a quantitative Cybersecurity Scoring and Continuous Monitoring of 3rd party vendors’ technology infrastructure in the Financial Services industry. To achieve this goal, financial institutions must leverage not only the newly created alliances within their industry but also thoroughly research the methods and techniques being deployed by the early cybersecurity scoring solutions on the market today. The particularity of the proposed scoring model in this report will be to capture and map the financial regulations into its build, which none of the early adopters in the cybersecurity scoring solutions is currently offering.
- Name
- Name Part
- Tanieu, Severin
- Role
- Role Term (marcrelator)
(authorityURI="http://id.loc.gov/vocabulary/relators", valueURI="http://id.loc.gov/vocabulary/relators/cre")
- Creator
- Name:
Personal
- Name Part
- Palazzi, Bernado
- Role
- Role Term:
Text
- Advisor
- Name:
Corporate
- Name Part
-
Brown University. School of Professional Studies. Department of Computer Science
- Role
- Role Term:
Text
- Sponsor
- Origin Information
- Copyright Date
- 2019
- Physical Description
- Extent
- 18 p.
- digitalOrigin
- born digital
- Note:
Capstone
- Capstone (EMCS)--Brown University, 2019
- Subject (fast)
(authorityURI="http://id.worldcat.org/fast/872484", valueURI="http://id.worldcat.org/fast/1033711")
- Topic
- Computer security
- Subject (Local)
- Topic
- Cyber security frameworks
- Subject (Local)
- Topic
- Security risk vector
- Subject (Local)
- Topic
- SSAE 16
- Subject (Local)
- Topic
- SOC 2
- Subject (Local)
- Topic
- ISO 27001/2
- Subject (Local)
- Topic
- NIST Cybersecurity framework
- Subject (Local)
- Topic
- Vendor assessment
- Subject (Local)
- Topic
- Security rating
- Subject (Local)
- Topic
- Vendor lifecycle
- Subject (Local)
- Topic
- CyberScore
- Subject (Local)
- Topic
- 23 NYCYRR500
- Subject (Local)
- Topic
- OCC
- Subject (Local)
- Topic
- FFIEC
- Subject (Local)
- Topic
- General Data Protection Regulation (GDPR)
- Type of Resource
- text
- Genre
- Critical Challenge Project
- Access Condition:
rights statement
(href="http://rightsstatements.org/vocab/InC/1.0/")
- In Copyright
- Access Condition:
restriction on access
- All rights reserved. Collection is open for research.
- Language
- Language Term (ISO639-2B)
- English
- Record Information
- Record Content Source (marcorg)
- RPB
- Record Creation Date
(encoding="iso8601")
- 20100429
- Identifier:
DOI
- 10.26300/sypv-n617