1. Prerequisites
Before starting this runbook, ensure the following:
- Third-party compromise notification received
- Vendor or supplier identified
- Incident ticket created
- Access to vendor inventory
- Access to identity and access management systems
- Access to cloud and SaaS audit logs
- Access to asset inventory
2. Step-by-Step Instructions
-
Validate Third-Party Relationship
Identify:
- Vendor name
- Service provided
- Business owner
- Criticality rating
- Contractual relationship
- Data handling responsibilities
Determine:
- Whether the organisation actively uses the vendor
- Whether services remain operational
- Whether the relationship is current
Document findings.
-
Identify Organisational Dependencies
Review:
- SaaS platforms
- Cloud services
- Managed service providers
- Software suppliers
- Development dependencies
- Security tooling
- Infrastructure providers
Determine:
- Which systems rely on the third party
- Which business processes are affected
Document impacted services.
-
Assess Third-Party Access
Review:
- User accounts
- Service accounts
- API integrations
- OAuth applications
- Federated identity relationships
- Privileged access
- Administrative access
Identify:
- Active access paths
- High-risk access
- Excessive permissions
Document findings.
-
Assess Data Exposure
Determine whether the third party has access to:
- Customer data
- Employee data
- Financial data
- Intellectual property
- Source code
- Security telemetry
- Authentication systems
Document:
- Data types
- Data classification levels
- Exposure risk
-
Review Authentication Activity
Review:
- Recent authentications
- Failed authentication attempts
- Administrative logins
- API activity
- Federated access activity
- Unusual login patterns
Identify suspicious activity associated with the third party.
-
Review Audit Logs
Review:
- Cloud audit logs
- SaaS audit logs
- Administrative activity logs
- Configuration changes
- Permission changes
- Service account activity
Identify evidence of:
- Unauthorised access
- Suspicious changes
- Unexpected activity
-
Assess Organisational Impact
Determine:
- Systems impacted
- Users impacted
- Business functions impacted
- Regulatory implications
- Operational risk
- Recovery complexity
Assign an impact rating.
-
Determine Containment Requirements
Assess whether:
- Third-party access should be suspended
- Service accounts should be disabled
- Tokens should be revoked
- API keys should be rotated
- Integrations should be disabled
Document recommendations.
-
Update Incident Record
Record:
- Third-party details
- Exposure assessment
- Access review findings
- Impact assessment
- Containment recommendations
Attach supporting evidence.
3. Post-Action
Upon completion:
- Ensure exposure assessment has been documented
- Ensure impacted systems have been identified
- Ensure access relationships have been reviewed
- Ensure containment recommendations are recorded
- Ensure incident ticket is updated
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
