This message was posted by a user wishing to remain anonymous
With the new CCPA regulation that now requires credit unions to conduct annual cybersecurity audits, Vendor Management/Third Party Risk Management will also be responsible for "overseeing service providers and third parties to ensure they also comply with cybersecurity standards."
How is everyone preparing to address this? Would cybersecurity questions that are embedded within annual security questionnaires sufficient? And besides contractual language, what else could we do to provide proof of oversight?
Thanks in advance for any insights!
-------------------------------------------