How to Manage Third-Party Risk in Cloud Platforms

128 views
•
February 27, 2020
by
RSAC Cybersecurity
YouTube video player
How to Manage Third-Party Risk in Cloud Platforms

TL;DR

Manage platform risk by identifying observable signs of trust, verifying that partners follow expected practices, and sharing relevant evidence transparently. Complete mapping of every party in a cloud-based value chain may be impossible, so security teams should focus on accountability, layered verification, and closing trust gaps across interconnected applications, services, providers, and customers.

Transcript

Thank you. Hi, everyone, and welcome to the session on nanotechnology, behavior and suppli-supply chains, managing risk at a platform level. And the speakers today is Edna Conway, V-VP Global Security, Risk and Compliance at Microsoft Azure, and Ofir Gadot, uh, PhD, CEO and founder of DUST Identity. Welcome, and happy to have you here. Thank you ve... Read More

Key Insights

  • Trust is the currency of the digital economy because platforms depend on relationships among providers, customers, applications, services, and third parties. Data remains important, but dependable participation requires evidence that organizations and technologies will behave according to shared expectations.
  • Cloud technology is the foundation of the platform economy described in the session. It supports business operations, daily activities, and government services while enabling greater productivity and reach, but it also increases dependence on providers whose underlying relationships may remain invisible.
  • Third-party risk is frequently unaccounted for because organizations may know their direct provider without knowing that provider's dependencies. Applications and services connect to growing numbers of outside parties, creating exposure that traditional views of a linear supply chain may not capture.
  • Platform opacity creates a house-of-mirrors problem in which each participant sees the ecosystem through a different lens. This can produce incomplete or false views of who contributes technology, services, security controls, and risk across interconnected value chains.
  • Complete value-chain mapping is impractical in a platform economy because organizations cannot reliably know or observe every participant. Risk management should therefore emphasize trustworthy indicators and verification instead of assuming that exhaustive visibility is attainable.
  • Indicia of trust are observable signs that a provider, product, or partner follows practices worthy of reliance. Organizations should decide which signs matter, request evidence from third parties, and identify comparable evidence they can offer customers and ecosystem partners.
  • Zero trust is presented as an incomplete description of real behavior because people and organizations continually make risk-based decisions that require some reliance. The practical objective is to verify relevant evidence, apply sound practices, and close specific trust gaps.
  • Security professionals need to become risk experts because platform security involves more than technical controls. They must evaluate dependencies, define suitable trust indicators, encourage transparent disclosure, verify partner practices, and apply layered measures that establish accountability across the ecosystem.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can organizations manage third-party risk in cloud platforms?

Organizations can manage third-party risk by defining observable signs of trust, asking providers for evidence, verifying that the evidence remains present, and disclosing their own relevant practices. Because complete knowledge of every downstream participant may be impossible, the approach should be layered and risk-based. Its purpose is to create accountability and close identifiable trust gaps across applications, services, providers, customers, and other ecosystem participants.

Q: What is unaccounted risk in a platform economy?

Unaccounted risk is exposure created by relationships or dependencies that an organization does not fully recognize in its risk assessment. A business may know its immediate cloud or service provider but lack visibility into the parties supporting that provider. The resulting opacity means applications and services can rely on an expanding network whose participants, controls, and responsibilities are not completely visible to customers or even to one another.

Q: Why is complete supply chain mapping difficult for platforms?

Complete mapping is difficult because platform-based applications and services connect to growing numbers of third parties, and those parties may depend on additional organizations. Each participant sees the network through a different lens, so no single organization necessarily possesses a complete view. The session therefore does not recommend relying exclusively on exhaustive mapping. It emphasizes trust indicators, verification, transparency, layered practices, and accountability as more practical responses.

Q: What are indicia of trust in third-party risk management?

Indicia of trust are observable signs that help an organization judge whether a third party, product, or platform deserves reliance. The session does not prescribe a universal checklist. Instead, it urges organizations to determine which indicators matter in their communities and enterprises, verify that those indicators exist, and transparently disclose comparable evidence to customers and partners so the wider ecosystem can share responsibility and accountability.

Q: Why is trust considered the currency of the digital economy?

Trust is considered the currency of the digital economy because digital platforms connect organizations and people who must rely on providers they may not fully see or understand. Data alone does not resolve whether those participants behave responsibly or maintain suitable practices. Platform relationships therefore depend on evidence, verification, transparency, and accountability that allow customers, providers, and third parties to make informed risk-based decisions despite incomplete visibility.

Q: How should security teams approach zero trust and verification?

Security teams should recognize that real activity still involves risk-based reliance rather than literal trust in nothing. People and organizations choose to use services, attend events, and work with third parties after assessing available information. The session recommends focusing on verification: define signs of trust, check that they are present, apply best practices, and address specific gaps through layered controls and shared accountability.

Q: What risks does cloud adoption create for supply chains?

Cloud adoption creates risk when essential applications and services depend on providers and downstream parties that customers cannot clearly identify. Cloud platforms enable productivity, reach, business operations, government services, and daily activities, but their interconnected structure can obscure responsibility. This opacity can leave some third-party exposures outside conventional risk assessments, requiring organizations to seek evidence, verify practices, disclose relevant information, and manage dependencies at the platform level.

Q: Why must security professionals become risk experts?

Security professionals must become risk experts because platform ecosystems cannot be protected solely by examining individual technical components. They need to understand how applications, services, cloud providers, customers, and third parties create shared exposure. Their role includes identifying unaccounted risk, deciding which trust indicators matter, verifying evidence, encouraging transparent disclosure, and selecting layered practices that close gaps while supporting necessary business and daily activities.

Summary & Key Takeaways

  • Cloud platforms support healthcare, transportation, logistics, retail, energy, connected factories, smart cities, government services, and daily life. Their reach improves productivity and access, but it also obscures the organizations and technologies behind applications and services, leaving customers unable to see every dependency within an expanding third-party network.

  • The platform economy creates unaccounted risk because organizations depend on third parties without always knowing who those parties use in turn. Different participants see different reflections of the ecosystem, producing a house-of-mirrors effect in which opacity can create incomplete or false views of responsibility, exposure, and trustworthiness.

  • Organizations cannot realistically map every participant in a platform-based value chain. They should instead define observable signs of trust, verify those signs, disclose their own practices transparently, and share evidence across the ecosystem. This layered, risk-based approach helps security professionals establish accountability and close gaps without assuming either complete trust or zero trust.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚