Build the vendor registry and find the one nobody owns
Task
Inventory the third parties a small estate depends on, including the ones nobody thinks of as vendors, set the monitoring cadence for each, and write down what offboarding each one would have to remove. The vendor nobody owns is the one whose attestation lapsed two years ago.
Steps
- List every third party your lab estate depends on. Push past the obvious: the operating system vendors, the package repositories, the container registry, the certificate authority, the DNS provider, the hypervisor vendor, and anything you download tooling from.
- Write
/tmp/vendors.csvwith the columnsvendor,service,data_they_hold,access_they_have,criticality,owner,last_assessed,next_review,evidence_type,single_point. - Set criticality from two questions: what happens to you if they are breached, and what happens if they simply stop.
- Set the review cadence from criticality, not uniformly: a critical vendor annually, a minor one every three years. For
evidence_type, name what you would rely on (questionnaire, attestation such as a SOC 2 Type II report, penetration test report, right-to-audit exercise) and note whether its scope would actually cover the service you use. - Identify the single points of failure: vendors whose loss would stop a business function with no alternative. Mark them
yesinsingle_point(nofor the rest), because the business continuity plan needs to know. - Write
/tmp/offboarding.md: for the three most critical vendors, every account, API key, token, OAuth grant or integration that would have to end with the contract. The registry is what makes offboarding complete. - Find the gaps: any vendor with no owner, no assessment date, or evidence older than its cadence. Those are the findings.
Verify
python3 - <<'PY'
import csv,re
rows=list(csv.DictReader(open('/tmp/vendors.csv')))
assert len(rows)>=8, 'fewer than eight third parties - push past the obvious ones'
noowner=[r['vendor'] for r in rows if not r['owner'].strip()]
nodate=[r['vendor'] for r in rows if not re.match(r'\d{4}-\d{2}-\d{2}', r['next_review'].strip())]
noev=[r['vendor'] for r in rows if not r['evidence_type'].strip()]
crit={r['criticality'].strip().lower() for r in rows}
print('criticality levels used:',crit)
assert len(crit)>=2, 'every vendor has the same criticality - the cadence cannot differ'
print('vendors with no owner:',noowner or 'none')
print('vendors with no next review:',nodate or 'none')
assert not noowner, 'unowned vendors are the finding - assign them'
assert not nodate, 'every vendor needs a next review date'
assert not noev, 'no assessment evidence named for: '+', '.join(noev)
PY
python3 -c "import csv;print(sum(r['single_point'].strip().lower()=='yes' for r in csv.DictReader(open('/tmp/vendors.csv'))),'single point(s) of failure marked')"
grep -ciE "token|api key|oauth|account" /tmp/offboarding.md
The assertions require at least eight third parties, a genuine spread of criticality, an owner and a review date on every row, and named evidence for each. Eight is deliberately more than people expect: the certificate authority, the DNS provider and the package repository are all third parties whose compromise reaches you directly, and almost nobody has them on a vendor list. The final grep confirms the offboarding list names the access itself.
Notes
The single points of failure are the rows that belong in the continuity plan. Your recovery capability is limited by theirs, and a business impact analysis that maps functions to internal systems and stops there has missed the vendor whose outage stops the function regardless of what your own estate is doing.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.