The Third Parties module helps you manage the cybersecurity risk that comes with vendors and partners. It is the inventory of every external entity that interacts with your organisation, with the documentation, classification and follow-up that supply-chain oversight requires.
1. Third-party profiles
Each third party gets a documented profile: its role, classification and organisational attributes. The dropdown values used across these fields come from your workspace's configuration catalogues (Databases module), so the vocabulary matches your organisation. Advanced filters make even a large vendor inventory easy to work through.
2. CIA levels of processed data
Classify the data each third party processes, information type by information type, on Confidentiality, Integrity and Availability. CSFaaS derives the resulting Security Objectives and the Overall Third Party Security Categorization, giving you a defensible criticality rating per vendor.
3. Related systems
Map which of your internal systems are involved in each third-party relationship. This mapping makes impact areas explicit and strengthens risk visibility on both sides.
4. Assessment and follow-up
From a third party you can trigger and follow risk assessments, send forms to collect information directly from the vendor (including external recipients by email), and attach evidences such as certifications or contractual documents.
5. Sharing with stakeholders
Invite individual stakeholders to a specific third party with Read or Write access. They see and work on that item only, without gaining access to the whole module: useful for the business owner of a single vendor relationship.
The third-parties chapter of this documentation covers profiles, CIA classification and vendor assessment in depth.
Privacy note. Personal details in this revision have been removed, masked or replaced for privacy. The original is retained privately.