MEDIA CONTACT
Marya Roddis, Vice President of Communications
O: 575.235.8228
marya@santa-fe-group.com
Santa Fe, NM — January 26, 2016 — Shared Assessments has released its updated 2016 Shared Assessments Program Tools, which allow risk management professionals to respond to the rapidly increasing security threats and vulnerabilities associated with outsourcing, Cloud, mobile and fourth party security issues. These assessment tools serve organizations regardless of size and industry, to meet the recent surge in regulatory, consumer and business scrutiny alongside rapidly increasing threats and vulnerabilities posed by third party service providers, which have led an onslaught of data breaches in recent months.
“The Shared Assessments Program Tools allow organizations to rigorously assess and manage IT, security, privacy and resiliency risk,” explains Seth Bailey, Director, Information Security of Iron Mountain and the Shared Assessments Program Chair. The tools are: the Standardized Information Gathering (SIG) questionnaire; Agreed Upon Procedures (AUP), used for standardized onsite assessments; and the Vendor Risk Management Maturity Model (VRMMM).
The tools provide a tangible gain in risk management, improving the risk posture at the service provider level over using proprietary questionnaires. The tools can be tailored to an organization’s unique interpretation of regulations, divisional needs and risk appetites.
Creating Sustainable Efficiencies in Today’s High Risk Environment
The Shared Assessments Program Tools have been aligned with a multitude of regulatory guidance and industry standards, most recently including: FFIEC Business Continuity Planning Handbook Appendix J (April 2015); PCI DSS – v3.1 (June 2015); ISO 22301:2012 – Societal security – Business continuity management systems – Requirements (May 2015); NIST Cybersecurity Framework and Special Publication 800-53 Revision 4 – Security and Privacy Controls for Federal Information Systems and Organizations (April 2013); AICPA Incident Response Plan (2004); DOJ Instruction – Incident Response Procedures for Data Breaches (published August 2013); FCC Computer Security Incident Response Guide (published December 2001)] HIPAA Incident Response and Reporting (published September 2011); NERC CIP-008-5 – Cyber Security – Incident Reporting and Response Planning (published July 2014); NIST Special Publication 800-61 Revision 2 – Computer Security Incident Handling Guide (published August 2012); and US-CERT Federal Incident Notification Guidelines (effective October 2014).
In addition, the 2016 Shared Assessments AUP includes an addendum to allow multiple outsourcers to collaborate and assess the risk controls of a single outsourcer. This content was developed through top-tier financial institutions who shared collective intelligence to develop and test an augmented AUP, specifically geared to a collaborative assessment that profiles the full and complete control environment using a substantiation-based, standardized, efficient methodology. Benefits of using the collaboratively developed, AUP for a larger set of common service providers include consistency, rigor and efficiency.
Updated 2016 Program Tools
The following updates are included in the 2016 release:
Pricing and Availability
The updated Program Tools are available now to all Shared Assessments Members and are included in the annual membership fee. Membership provides opportunities to deepen vendor risk management expertise through members-only meetings, events, teleconferences and regular cross-industry working groups that discuss best practices, new standards and guidelines and the regulatory climate. Non-members can purchase the Shared Assessments Tools either as a bundle or separately by visiting https://sharedassessments.org/store/.
“The Program Tools create sustainable efficiencies around the implementation of standardized, robust, tested strategies and processes,” says Cathy Allen, Chairman and CEO of the Santa Fe Group. “Applying the tools increases rigor, consistency and speed, resulting in cost savings in the control assessment process for both the outsourcing organization and the service provider. This, in turn, also allows organizations to redirect resources away from assessment costs and toward control and monitoring by limiting site visit and annual review man hours.”
About the Shared Assessments Program
The Shared Assessments Program is the trusted source in global third party risk management, with resources to effectively manage the critical components of the vendor risk management lifecycle; creating efficiencies and lowering costs for all participants; kept current with regulations, industry standards and guidelines, and the current threat environment; adopted globally across a broad range of industries both by service providers and their customers. Through membership and use of the Shared Assessments Program Tools (the Agreed Upon Procedures (AUP), Standardized Information Gathering (SIG) questionnaire and Vendor Risk Management Maturity Model (VRMMM)), Shared Assessments offers companies and their service providers a faster, more efficient and less costly means of conducting rigorous assessments of controls for IT and data security, privacy and business continuity. The Shared Assessments Program is managed by The Santa Fe Group (www.santa-fe-group.com), a strategic advisory company based in Santa Fe, New Mexico. For more information on Shared Assessments, please visit https://sharedassessments.org.