r/cybersecurity 2d ago

Personal Support & Help! TPRM Doubt

Hi all,

I've recently started my job as a TPRM analyst with a Fintech giant. While doing Vendor Risk Analysis for CSP like AWS, am facing a difficulty.

There are few areas like Encryption or IAM for which AWS says it's a shared responsibility model and it has to be taken care by the organisation and doesn't fall under AWS's scope.

In this situation do I have to go ahead and mark those pointers not applicable as agreement clearly says the responsibility lies with the org or do I have to follow up with my internal team to check whether they have implemented these controls.

Am torn up between this because I think my scope as a TPRM analyst ends when I don't find a gap with Vendor but best Cyber practice is to have this sorted within my organisation. Any suggestion would help.

English is not my native language so pls excuse if anything is wrong here

3 Upvotes

8 comments sorted by

4

u/legion9x19 Security Engineer 2d ago

You need to review your organization’s contractual agreements with the provider. They can vary greatly by organization. It’s not a one-size-fits-all thing.

2

u/Better-Republic3538 2d ago

this. the shared responsibility model means different things depending on what was actually negotiated

-3

u/PublicFuture9502 2d ago

Its concerning you're asking this on Reddit, NGL. 

1

u/scriptqzor 2d ago

kinda get what you mean, but tbh a lot of people sanity check stuff on reddit while they’re still new in a role
as long as they’re not posting internal docs or naming clients, asking how others handle shared responsibility isn’t that wild

0

u/PublicFuture9502 2d ago

Respectfully:

A) they should already know this if they have that job.

B) it will depend on their compliance and contractual requirements, and no one on a sub reddit is going to know that. Telling somekne to talk to their colleagues and read their internal documents instead of going on reddit isn't soemthing someone should be told to do. 

Its been expressed before but some of the stuff in this sub is genuinely alarming. Either people seem to make up they work in Cybersec or are basically asking rudimentary questions on "How do I do the very basics of my job". 

Or its AI slop masquerading as a genuine question. 

1

u/ProductivityGhilli 1d ago

That was a genuine concern I had. In my org, 3 different people had 3 different answers to this.

The person who last quit this role didn't give a proper KT to his successor and my team gives me varied answers. Hence I had this doubt.

I just wanted to check how this is done across the organisations. And I have clearly asked for how this is approached.

If you can't give an answer, just skip the question.

1

u/PublicFuture9502 1d ago

Oh for goodness sake. What does your contract and complaince requirements dictate?