Fastly, a content delivery network service widely used by web publishers, experienced an outage on June 8, 2021 that had global consequences with major news sites, Amazon, and even the United Kingdom’s government websites impacted. Although not cybersecurity related, this outage still provides an example of why organizations that rely on third parties to deliver critical services should continually assess the business resilience practices of those suppliers.
At a minimum, a third-party business resilience questionnaire should assess:
To determine a baseline of business resilience practices, Prevalent recommends that organizations require all their critical suppliers to answer the following 10 questions. These questions are meant to be a starting point; the answers should dictate next steps and vulnerable parts of the vendor’s business resilience plan should be addressed immediately.
Questions | Potential Responses |
---|---|
1) Does your organization have a Business Resilience Plan in place? Which of the following apply? Please select all that apply. |
a) We have a documented Business Resilience plan or similar in place. |
2) Which of the following aspects are included within the Business Resilience Plan? Please select all that apply. |
a) Activation criteria |
3) Has the organization identified call trees for both internal and external parties? Please select all that apply. |
a) Our Business Resilience Plan includes communication call trees. |
4) Which of the following are applicable when describing your organization's approach to conducting Business Impact Assessments? Please select all that apply. |
a) Impact assessments have been conducted on all systems, assets, and functions. |
5) Does your organization have a dedicated system outage plan in place? If no, is your organization creating one? Please select a single response. |
a) Yes, we have developed an outage plan, as part of our wider business resilience planning. |
6) Does your organization’s Incident Management Plan consider the response to potential non-cyber outages? Please select all that apply. |
a) We have a formally documented Incident Management Plan. |
7) At what level within your organization are decisions being made concerning continuity and outage planning? Please select all that apply. |
a) Decisions concerning continuity planning are managed at a board level. |
8) In the case of an outage, will Service Level Agreements (SLAs) with customers be adjusted in line with the impact of the outage? Please select all that apply. |
a) We will adjust our SLAs for all critical and non-critical services that have been impacted, based on our business impact analysis. |
9) What is your organization's timeline for providing accurate and up-to-date information to customers if services are impacted? Please select all that apply. |
a) We provide initial communication to our customers upon activation of our outage plan. |
10) Which of the following processes does your organization have in place for public communications? Please select all that apply. |
a) Public statement is made available. |
A critical supplier’s or 4th party’s outage can have a domino effect on your own organization’s ability to deliver products and services, with revenue, customer satisfaction and more at risk. Get started assessing your critical third parties’ processes for responding to crises with our free business resilience resources or contact us for a strategy session.
Effectively manage third-party cybersecurity incidents with a well-defined incident response plan.
09/24/2024
Why third-party breaches are on the rise, who is being affected, and what you can do...
09/20/2024
Use these 6 tips to improve your third-party breach response procedures.
09/17/2024