Classify vendors by consequence and dependency. Consider the business service supported, sensitive data handled, privileged or network access, production integration, concentration risk, substitutability, expected outage tolerance and recovery dependency. Use the criticality result to scale due diligence, evidence requests, monitoring, contract controls and incident coordination.
External reference
Current final publication with updates through November 2024. It integrates cybersecurity supply-chain risk management into enterprise risk activities and addresses supplier/product/service risk assessment and treatment.
Primary source →Practical workflow
Identify business dependence
Record the service owner, supported process, affected customers and acceptable disruption window.
Map technical dependence
Record data classes, accounts, privileges, integrations, network paths, hosted assets and administrative access.
Assess concentration and substitutability
Identify single points of external dependency, sub-tier concentration and practical alternatives or exit constraints.
Assign criticality
Use transparent criteria that can be reviewed and updated when the service, access or business impact changes.
Scale assurance
Increase evidence depth, monitoring cadence, incident requirements and resilience testing for the most consequential dependencies.
Relevant Cybatar sources
Claim boundary
A criticality tier is a prioritisation aid, not a security rating. It should be based on the organisation’s dependency and consequence context and reviewed after material service, access or architecture changes.
These pages are Cybatar-authored third-party cyber risk and resilience guidance. NIST publications are used as external references. The mappings are not NIST validations, certifications, endorsements, legal opinions or statements that a supplier or deployment is secure.