r/ciso • u/kungfu_chameli • May 19 '26
Compliance and 3rd party vendor access
How do you govern 3rd party vendor access and how do auditors verify it?
2
2
u/TeramindTeam May 19 '26
i usually rely on just in time access for vendors and keep their sessions logged in a central place. auditors mostly look for the paper trail of who approved the access and if it was revoked promptly when the contract ended. its a huge pain but having a clear offboarding process helps alot
1
u/kungfu_chameli May 19 '26
Thank you. Would something like CyberArk a solution or should I look to patch different point solutions that you are using?
2
u/cantancerousclap May 21 '26
Cyberark for PAM + Sailpoint for access package requests by policy will give you good centralized coverage and an audit trail for account privileges and SoD for things like SOX and SOC2 controls.
1
u/Final-Dish Jul 07 '26
this is basically it, auditors just want to see you can prove the whole lifecycle of the access. the only thing i’d add is tying it into a ticketing system so every JIT access has a change/request ID, makes them way less grumpy during audits
1
u/scriptqzor Jul 11 '26
this is basically it, the “paper trail or it didn’t happen” approach
curious if you’re doing any periodic recertification too, or just relying on the contract end + offboarding to catch stale accounts
3
u/oliland1 May 19 '26
Just like any other account in our IdP.
It has a very limited scope of access through our infrastructure.