Haymarket Media, Inc.
Mobile Version Subscribe Contact Us About Us Advertising Editorial SC UK SC Aus/NZ
SC Magazine
  • Home
  • News
    •  Features
    •  Opinions
    •  Newsletters
    •  Sectors
    •  Company Moves
  • Products
    •  First Looks
    •  Reviews
    •  Group Tests
    •  About Reviews
  • Blogs
    •  The News Team Blog
    •  The Data Breach Blog
  • Buyers Guide
  • Whitepapers
  • Jobs
  • Events
    •  SC World Congress
    •  Awards
    •  Podcasts
    •  Digital Download
    •  Editorial Webcasts
    •  Vendor Webcasts
    •  eConference
  • Subscribe
    •  Newsletters
    •  Subscribe to SC
  • Issue Archive
  • Topic Center:
  • Email Security
  • Compliance
  • Patch Management
  • Financial Services
  • Health Care
  • Retail
Subscribe to our RSS feeds RSS | Login | Register  
Home > The SC Magazine Newsteam Blog
The SC Magazine Newsteam Blog

Know thy vendor

time Posted May 15, 2008 * Comments(0)

Just how well do you know the vendors who supply your information technology products and services? The answer isn’t always as clear you one might think, and this lack of due diligence can have far-reaching implications for organizations’ data-protection strategies.

I, for instance, know of one successful, but now defunct, privately held vendor of software and hosting services whose owner was indicated by the FBI for alleged income tax evasion involving a brother. The capper: The brother was a known terrorist associated with Palestinian Islamic Jihad.

Yet this company listed many well-known organizations — the U.S. unit of a large European brewery, a large financial services company and a major manufacturer of fine china — among its customers. There’s no indication any of the vendor misused the customer data it had access to, but think about the possibilities.

Not performing a thorough background check of suppliers is common, according to R.M. “Reggie” Tracy, a former FBI special agent and owner of The Privacy Trust Group, an ID theft prevention and advocacy organization. When hiring a vendor, “Do companies verify that a suppler or vendor was a legally register business entity?,” she asked.

“In what state are they registered? Have complaints been lodged against the vendor with the Better Business Bureau? The State Attorney Generals? The FTC? Did they even check on any of this?  Did they at least “google” the company name or registered agent on their website to see what complaints may have been made by earlier customers for the same company? Or to find out other information about the company or registered agent that may be of concern?”

She believes that most companies fail to find out these “simple details” about their vendors and suppliers. “It’s mind boggling,” she said.

Following what she calls information-protection best practices (IPBP) can help, she said. “Organizations must identify the appropriate IPBP for their industry and environment, document these in corporate-wide policies and procedures (for employees, networks or systems) and then fully implement them throughout their organization,” she added.

“It’s only a matter of time before more companies of all sizes begin to understand the potential cost of failure in information protection,” she said. “We’re seeing multi-million dollar lawsuits against companies who fail to employ widely accepted best practices.

“Granted, not everyone knows or understands the implications of these sometimes simple, even inexpensive best practices,” Tracy emphasized. “But that is no excuse for failing to find out these best practices.”

Related Posts
  • Breaking: Laptop stolen from Deloitte & Touche vendor may contain personal data on partners and principals
    We're trying to get the specifics, but a Deloitte spokeswoman has confirmed for SCMagazineUS.com tha...
  • Worth recognition
    Kudos to Mobile Armor, a data encryption vendor, for this week’s good deed. The St. Louis-based...
  • Exploit out for McAfee bug
    Yesterday, we told you about a flaw in a list of McAfee products, which, to its credit, the AV vendo...
  • Easing privacy concerns will be a hurdle for Google’s web-based storage service
  • Dot your Is and cross your Ts

Filed under: Uncategorized

time The SC Magazine Newsteam Blog

Search This Blog:  


Categories
  • Apple
  • Breaches
  • Browser flaws
  • Compliance
  • Consumer threats
  • Education
  • Email Security
  • Emerging threats
  • Finance
  • Government
  • Groundbreakers and newsmakers
  • Health care
  • High tech
  • IM
  • Industry reports
  • Lawbreakers
  • Legal and professional services
  • Manufacturing
  • Mergers and acquisitions
  • Microsoft
  • Mobile and Endpoint Security
  • Non-Microsoft patches
  • Non-profit
  • Open source
  • Opinion
  • Patch Management
  • Patch Tuesday
  • Personnel moves
  • Phishing
  • Piracy
  • Privacy
  • Product news
  • Rootkits
  • SC Magazine
  • SC Magazine Blogs
  • Spam
  • The insider threat
  • Trojans
  • Uncategorized
  • Vista
  • Vulnerabilities
  • Worms
Authors
  • Angela Moscaritolo (1)
  • Chuck Miller (10)
  • Dan Kaplan (49)
  • Greg Masters (19)
  • Jim Carr (1)
Archives
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • Blogroll

    • Anton Chuvakin Blog
    • Computer Defense
    • Hacker Webzine
    • MacUser
    • Marco Ramilli’s Blog
    • Michael R. Farnum
    • SecGuru
    • The IT Security Guy
    • WordPress.com
    • WordPress.org
Home | News | Newsletters | Products | Blogs | Lists | Jobs | Events | Subscribe | Contact Us | About Us | Advertising | Editorial | Subscribe to our RSS feedsRSS

This material may not be published, broadcast, rewritten or redistributed in any form without prior authorization.

Your use of this website constitutes acceptance of Haymarket Media's Privacy Policy and Terms & Conditions