Skip to main content

Best Practices for Managing Third-Party Identity and Access Management

Vendors, partners, and others need to be managed appropriately to minimize risk to healthcare organization

Health-ISAC has released Best Practices for Managing Third-Party Identity and Access Management, the 12th white paper in an ongoing series for CISOs on Identity & Access Management (IAM).

The health sector is complex. Health organizations have more complicated facilities and third-party maintenance issues than most retailers, security requirements to match government organizations, and an array of devices reliant on third parties for maintenance that would rival manufacturing. All of this to say that this disparate ecosystem needs support from third parties for use cases that run the gamut.

For many of these systems, it’s more than just an individual with a toolbox to fix things or perform maintenance. Many systems and devices used in healthcare have microprocessors and typically connect to a network, which requires remote access by third parties. Third-party IAM issues go far beyond provisioning a new account in a directory. The account needs to be managed to enable access to the necessary systems with the appropriate roles and privileges. Depending on the IT infrastructure of the organization, this can be challenging.

This paper will:

  • Break down the challenges of third party IAM

  • Define best practices for health sector organizations to mitigate threats to third-party IAM systems

  • Leverage use cases to define the application of these best practices in real-world scenarios

 

Read and/or download the white paper.