P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

People and organisations

Supplier (vendor): what it is and how it is attacked

Another organisation with access to your systems.

Also known as

  • vendor
  • third party
  • contractor
  • MSP

Typing any of them into the editor finds this object.

Why it matters on a security diagram

Their security becomes yours the moment you grant them access, and you rarely get to inspect it.

How it gets attacked, and what reduces it

How it gets attacked

  • Standing access that outlives the engagement
  • Compromise of the supplier, reaching all of their customers

What reduces it

  • Time-bound their access and remove it at the end of the engagement rather than on trust
  • Require them to notify you of their own incidents, in the contract
  • Give them the narrowest access that does the job, and record what it reaches

Where it sits

Group
People and organisations · The humans and the entities they belong to.
Whose side, by default
Bystander · No relationship with us and no choice in the matter: an unwitting hosting provider, a stranger's compromised machine.
Catalogue identifier
supplier

Reviewed . CC BY 4.0.

Others in people and organisations

The people and organisations group carries every object in it, including the ones with no page of their own.

Supplier on your own diagram

Open the editor, press N, and type vendor. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker