Have you established a formal program to ensure third-party stakeholders (suppliers, customers, partners) understand their cybersecurity roles and responsibilities?
Explanation
Educating external parties on their security duties is the focus here: whether you run a formal program ensuring suppliers, customers, and partners understand their cybersecurity roles and responsibilities. Effective third-party security awareness helps prevent incidents caused by external stakeholders who may not be familiar with your security requirements or who might inadvertently introduce risks.
Evidence could include: third-party security training materials, signed security responsibility acknowledgments, onboarding documentation for partners that includes security responsibilities, security requirements in contracts, or records of security awareness sessions conducted with external stakeholders.
Context
- Function
- PR: PROTECT
- Category
- PR.AT: Awareness and Training
- Sub-Category
- Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
Related questions
- Does your organization provide cybersecurity awareness and training to all users with access to non-public resources?
- Does your organization provide comprehensive security awareness training that covers social engineering recognition, attack reporting procedures, acceptable use policies, and basic cyber hygiene practices?
- Does your organization clearly communicate the consequences of cybersecurity policy violations to all employees and stakeholders?
- Does your organization regularly assess employees' cybersecurity awareness through testing or evaluation?
- Does your organization require annual refresher training for all employees to reinforce existing security practices and introduce new ones?
- Has the organization identified specialized roles that require additional cybersecurity training beyond the baseline security awareness program?

