Privileged vendors deserve privileged controls
A supplier with administrative access should be treated like an administrator, because that is what they are.
Brokered access rather than standing credentials, per-person identity rather than a shared account, time-bound sessions, recording. All of which is normal for internal administrators and rarely applied to external ones, despite the external ones being harder to monitor and easier to compromise.
More on Third-party risk
- Security clauses need operational follow-throughWire the clause to something
- Shared responsibility should name the seamName the join
- Supplier notification affects your response clockThey hold your start button
- Exit plans are security controlsThe pipe that goes back
- CI/CD secretsIt has to reach everything
- SBOMsThe list, and the verdict
