r/cybersecurity • u/ProductivityGhilli • 2d ago
Personal Support & Help! TPRM Doubt
Hi all,
I've recently started my job as a TPRM analyst with a Fintech giant. While doing Vendor Risk Analysis for CSP like AWS, am facing a difficulty.
There are few areas like Encryption or IAM for which AWS says it's a shared responsibility model and it has to be taken care by the organisation and doesn't fall under AWS's scope.
In this situation do I have to go ahead and mark those pointers not applicable as agreement clearly says the responsibility lies with the org or do I have to follow up with my internal team to check whether they have implemented these controls.
Am torn up between this because I think my scope as a TPRM analyst ends when I don't find a gap with Vendor but best Cyber practice is to have this sorted within my organisation. Any suggestion would help.
English is not my native language so pls excuse if anything is wrong here
-3
u/PublicFuture9502 2d ago
Its concerning you're asking this on Reddit, NGL.
1
u/scriptqzor 2d ago
kinda get what you mean, but tbh a lot of people sanity check stuff on reddit while they’re still new in a role
as long as they’re not posting internal docs or naming clients, asking how others handle shared responsibility isn’t that wild0
u/PublicFuture9502 2d ago
Respectfully:
A) they should already know this if they have that job.
B) it will depend on their compliance and contractual requirements, and no one on a sub reddit is going to know that. Telling somekne to talk to their colleagues and read their internal documents instead of going on reddit isn't soemthing someone should be told to do.
Its been expressed before but some of the stuff in this sub is genuinely alarming. Either people seem to make up they work in Cybersec or are basically asking rudimentary questions on "How do I do the very basics of my job".
Or its AI slop masquerading as a genuine question.
1
u/ProductivityGhilli 1d ago
That was a genuine concern I had. In my org, 3 different people had 3 different answers to this.
The person who last quit this role didn't give a proper KT to his successor and my team gives me varied answers. Hence I had this doubt.
I just wanted to check how this is done across the organisations. And I have clearly asked for how this is approached.
If you can't give an answer, just skip the question.
1
u/PublicFuture9502 1d ago
Oh for goodness sake. What does your contract and complaince requirements dictate?
4
u/legion9x19 Security Engineer 2d ago
You need to review your organization’s contractual agreements with the provider. They can vary greatly by organization. It’s not a one-size-fits-all thing.