GE Vernova
Third Party Risk Management Control Guidance
Pages
4
Time to read
6 mins
Publication
Language
English
Pages
4
Time to read
6 mins
Publication
Language
English
This document is a control guidance report focused on third-party risk management, specifically addressing encryption practices. It outlines eight key findings related to encryption, each accompanied by a risk rating and control questions. The report emphasizes the importance of using cryptographic keys for single purposes, periodic rotation of keys, and secure storage in protected key vaults. It details the risks associated with improper key management, such as increased vulnerability to cracking and unauthorized access. Additionally, it specifies the need for GEV data to be stored in encrypted form and transmitted securely over public networks using protocols like TLS. Each section includes acceptable compensating controls and the necessity for documentation or evidence to demonstrate compliance with these controls. The document serves as a framework for organizations to assess and enhance their encryption practices, ensuring data integrity and security in third-party interactions.