Supplier (vendor): what it is and how it is attacked
Another organisation with access to your systems.
Also known as
- vendor
- third party
- contractor
- MSP
Typing any of them into the editor finds this object.
Why it matters on a security diagram
Their security becomes yours the moment you grant them access, and you rarely get to inspect it.
How it gets attacked, and what reduces it
How it gets attacked
- Standing access that outlives the engagement
- Compromise of the supplier, reaching all of their customers
What reduces it
- Time-bound their access and remove it at the end of the engagement rather than on trust
- Require them to notify you of their own incidents, in the contract
- Give them the narrowest access that does the job, and record what it reaches
Where it sits
- Group
- People and organisations · The humans and the entities they belong to.
- Whose side, by default
- Bystander · No relationship with us and no choice in the matter: an unwitting hosting provider, a stranger's compromised machine.
- Catalogue identifier
- supplier
Reviewed . CC BY 4.0.
Others in people and organisations
The people and organisations group carries every object in it, including the ones with no page of their own.
Supplier on your own diagram
Open the editor, press N, and type vendor. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.
Open the diagram maker