{
    "ok": true,
    "doi": "10.46243/jst.2025.v10.i07.pp01-09",
    "events": [
        {
            "seq": 1,
            "kind": "register",
            "at": "2026-09-29 22:00:32",
            "by": "Administrator (admin)",
            "by_kind": "user",
            "note": "registered at Crossref; record read from api.crossref.org",
            "changes": [
                {
                    "path": "abstract.value",
                    "from": null,
                    "to": "Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security."
                },
                {
                    "path": "agents.0.name.family",
                    "from": null,
                    "to": "Ayoub Alfawzan"
                },
                {
                    "path": "agents.0.name.given",
                    "from": null,
                    "to": ""
                },
                {
                    "path": "agents.0.role",
                    "from": null,
                    "to": "author"
                },
                {
                    "path": "agents.0.sequence",
                    "from": null,
                    "to": "first"
                },
                {
                    "path": "agents.1.name.family",
                    "from": null,
                    "to": "Omer Alrwais"
                },
                {
                    "path": "agents.1.name.given",
                    "from": null,
                    "to": ""
                },
                {
                    "path": "agents.1.role",
                    "from": null,
                    "to": "author"
                },
                {
                    "path": "agents.1.sequence",
                    "from": null,
                    "to": "additional"
                },
                {
                    "path": "agents.2.name.org",
                    "from": null,
                    "to": "Longman Publishers"
                },
                {
                    "path": "agents.2.role",
                    "from": null,
                    "to": "publisher"
                },
                {
                    "path": "characters.0",
                    "from": null,
                    "to": "Language"
                },
                {
                    "path": "container.identifiers.0.medium",
                    "from": null,
                    "to": "electronic"
                },
                {
                    "path": "container.identifiers.0.type",
                    "from": null,
                    "to": "ISSN"
                },
                {
                    "path": "container.identifiers.0.value",
                    "from": null,
                    "to": "2456-5660"
                },
                {
                    "path": "container.issue",
                    "from": null,
                    "to": "7"
                },
                {
                    "path": "container.pages.first",
                    "from": null,
                    "to": "1"
                },
                {
                    "path": "container.pages.last",
                    "from": null,
                    "to": "9"
                },
                {
                    "path": "container.titles.0.type",
                    "from": null,
                    "to": "PrincipalTitle"
                },
                {
                    "path": "container.titles.0.value",
                    "from": null,
                    "to": "Journal of Science &amp; Technology"
                },
                {
                    "path": "container.titles.1.type",
                    "from": null,
                    "to": "AbbreviatedTitle"
                },
                {
                    "path": "container.titles.1.value",
                    "from": null,
                    "to": "J. sci. technol."
                },
                {
                    "path": "container.type",
                    "from": null,
                    "to": "Journal"
                },
                {
                    "path": "container.volume",
                    "from": null,
                    "to": "10"
                },
                {
                    "path": "dates.date_type",
                    "from": null,
                    "to": "PublicationDate"
                },
                {
                    "path": "dates.online",
                    "from": null,
                    "to": "2025-07-18"
                },
                {
                    "path": "dates.published",
                    "from": null,
                    "to": "2025-07-18"
                },
                {
                    "path": "doi",
                    "from": null,
                    "to": "10.46243/jst.2025.v10.i07.pp01-09"
                },
                {
                    "path": "format",
                    "from": null,
                    "to": "smartscholars-doi-metadata/1.0"
                },
                {
                    "path": "identifiers.0.type",
                    "from": null,
                    "to": "DOI"
                },
                {
                    "path": "identifiers.0.value",
                    "from": null,
                    "to": "10.46243/jst.2025.v10.i07.pp01-09"
                },
                {
                    "path": "license.applies_to",
                    "from": null,
                    "to": "unspecified"
                },
                {
                    "path": "license.start",
                    "from": null,
                    "to": "2025-07-18"
                },
                {
                    "path": "license.url",
                    "from": null,
                    "to": "https://creativecommons.org/licenses/by/4.0"
                },
                {
                    "path": "links.0.primary",
                    "from": null,
                    "to": true
                },
                {
                    "path": "links.0.return_type",
                    "from": null,
                    "to": "text/html"
                },
                {
                    "path": "links.0.url",
                    "from": null,
                    "to": "https://jst.org.in/index.php/pub/article/view/1332"
                },
                {
                    "path": "links.1.purpose",
                    "from": null,
                    "to": "text-mining"
                },
                {
                    "path": "links.1.return_type",
                    "from": null,
                    "to": "application/pdf"
                },
                {
                    "path": "links.1.url",
                    "from": null,
                    "to": "https://jst.org.in/index.php/pub/article/download/1332/1008"
                },
                {
                    "path": "modes.0",
                    "from": null,
                    "to": "Visual"
                },
                {
                    "path": "record.issue_number",
                    "from": null,
                    "to": 1
                },
                {
                    "path": "record.registered",
                    "from": null,
                    "to": "2025-08-26"
                },
                {
                    "path": "record.registrant",
                    "from": null,
                    "to": "Longman Publishers"
                },
                {
                    "path": "record.source",
                    "from": null,
                    "to": "crossref-api"
                },
                {
                    "path": "record.source_agency",
                    "from": null,
                    "to": "Crossref (member 25296)"
                },
                {
                    "path": "record.updated",
                    "from": null,
                    "to": "2026-09-07"
                },
                {
                    "path": "references.0.doi",
                    "from": null,
                    "to": "10.1109/itsim.2008.4631922"
                },
                {
                    "path": "references.0.key",
                    "from": null,
                    "to": "ref1"
                },
                {
                    "path": "references.0.unstructured",
                    "from": null,
                    "to": "Aris, S. R. H. S., Arshad, N. H., & Mohamed, A. (2008). Conceptual framework on risk management in IT outsourcing projects. management, 36(37), 37-38"
                },
                {
                    "path": "references.1.doi",
                    "from": null,
                    "to": "10.1080/1097198x.2021.1993725"
                },
                {
                    "path": "references.1.key",
                    "from": null,
                    "to": "ref2"
                },
                {
                    "path": "references.1.unstructured",
                    "from": null,
                    "to": "Bhatti, B. M., Mubarak, S., & Nagalingam, S. (2021). Information security risk management in it outsourcing–a quarter-century systematic literature review. Journal of Global Information Technology Management, 24(4), 259-298"
                },
                {
                    "path": "references.2.key",
                    "from": null,
                    "to": "ref3"
                },
                {
                    "path": "references.2.unstructured",
                    "from": null,
                    "to": "Boggavarapu, S. (2021). The Effect of Third-Party Service Providers on Information Security Breaches at Financial Institutions (Doctoral dissertation, University of the Cumberlands)"
                },
                {
                    "path": "references.3.doi",
                    "from": null,
                    "to": "10.1365/s43439-021-00029-4"
                },
                {
                    "path": "references.3.key",
                    "from": null,
                    "to": "ref4"
                },
                {
                    "path": "references.3.unstructured",
                    "from": null,
                    "to": "Bomhard, D., & Daum, A. (2021). Cybersecurity in outsourcing and cloud computing: a growing challenge for contract drafting, International Cybersecurity Law Review, 2(1), 161-171"
                },
                {
                    "path": "references.4.key",
                    "from": null,
                    "to": "ref5"
                },
                {
                    "path": "references.4.unstructured",
                    "from": null,
                    "to": "Haller, J., & Wallen, C. (2016). Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach, Carnegie Mellon University Software Engineering Institute. Ayoub Alfawzan, Omer Alrwais: Contractual Agreement Aspect of Third-party Risk Management in Information Security"
                },
                {
                    "path": "references.5.key",
                    "from": null,
                    "to": "ref6"
                },
                {
                    "path": "references.5.unstructured",
                    "from": null,
                    "to": "Singh, A. (2009). Improving Information Security Risk Management [Unpublished doctoral dissertation]. University of Minnesota"
                },
                {
                    "path": "references.6.doi",
                    "from": null,
                    "to": "10.2139/ssrn.3763399"
                },
                {
                    "path": "references.6.key",
                    "from": null,
                    "to": "ref7"
                },
                {
                    "path": "references.6.unstructured",
                    "from": null,
                    "to": "VanHoy, J. (2021). Third Party Risk Management. Available at SSRN 3763399"
                },
                {
                    "path": "referent",
                    "from": null,
                    "to": "Creation"
                },
                {
                    "path": "structural_type",
                    "from": null,
                    "to": "Digital"
                },
                {
                    "path": "titles.0.type",
                    "from": null,
                    "to": "PrincipalTitle"
                },
                {
                    "path": "titles.0.value",
                    "from": null,
                    "to": "Contractual Agreement Aspect of Third-party Risk Management in Information Security"
                },
                {
                    "path": "type",
                    "from": null,
                    "to": "JournalArticle"
                }
            ],
            "record_after": {
                "format": "smartscholars-doi-metadata/1.0",
                "doi": "10.46243/jst.2025.v10.i07.pp01-09",
                "referent": "Creation",
                "type": "JournalArticle",
                "structural_type": "Digital",
                "modes": [
                    "Visual"
                ],
                "characters": [
                    "Language"
                ],
                "titles": [
                    {
                        "value": "Contractual Agreement Aspect of Third-party Risk Management in Information Security",
                        "type": "PrincipalTitle"
                    }
                ],
                "identifiers": [
                    {
                        "type": "DOI",
                        "value": "10.46243/jst.2025.v10.i07.pp01-09"
                    }
                ],
                "agents": [
                    {
                        "role": "author",
                        "name": {
                            "given": "",
                            "family": "Ayoub Alfawzan"
                        },
                        "sequence": "first"
                    },
                    {
                        "role": "author",
                        "name": {
                            "given": "",
                            "family": "Omer Alrwais"
                        },
                        "sequence": "additional"
                    },
                    {
                        "role": "publisher",
                        "name": {
                            "org": "Longman Publishers"
                        }
                    }
                ],
                "dates": {
                    "published": "2025-07-18",
                    "date_type": "PublicationDate",
                    "online": "2025-07-18"
                },
                "container": {
                    "type": "Journal",
                    "titles": [
                        {
                            "value": "Journal of Science &amp; Technology",
                            "type": "PrincipalTitle"
                        },
                        {
                            "value": "J. sci. technol.",
                            "type": "AbbreviatedTitle"
                        }
                    ],
                    "identifiers": [
                        {
                            "type": "ISSN",
                            "value": "2456-5660",
                            "medium": "electronic"
                        }
                    ],
                    "volume": "10",
                    "issue": "7",
                    "pages": {
                        "first": "1",
                        "last": "9"
                    }
                },
                "links": [
                    {
                        "url": "https://jst.org.in/index.php/pub/article/view/1332",
                        "return_type": "text/html",
                        "primary": true
                    },
                    {
                        "url": "https://jst.org.in/index.php/pub/article/download/1332/1008",
                        "purpose": "text-mining",
                        "return_type": "application/pdf"
                    }
                ],
                "abstract": {
                    "value": "Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security."
                },
                "license": {
                    "url": "https://creativecommons.org/licenses/by/4.0",
                    "start": "2025-07-18",
                    "applies_to": "unspecified"
                },
                "references": [
                    {
                        "key": "ref1",
                        "doi": "10.1109/itsim.2008.4631922",
                        "unstructured": "Aris, S. R. H. S., Arshad, N. H., & Mohamed, A. (2008). Conceptual framework on risk management in IT outsourcing projects. management, 36(37), 37-38"
                    },
                    {
                        "key": "ref2",
                        "doi": "10.1080/1097198x.2021.1993725",
                        "unstructured": "Bhatti, B. M., Mubarak, S., & Nagalingam, S. (2021). Information security risk management in it outsourcing–a quarter-century systematic literature review. Journal of Global Information Technology Management, 24(4), 259-298"
                    },
                    {
                        "key": "ref3",
                        "unstructured": "Boggavarapu, S. (2021). The Effect of Third-Party Service Providers on Information Security Breaches at Financial Institutions (Doctoral dissertation, University of the Cumberlands)"
                    },
                    {
                        "key": "ref4",
                        "doi": "10.1365/s43439-021-00029-4",
                        "unstructured": "Bomhard, D., & Daum, A. (2021). Cybersecurity in outsourcing and cloud computing: a growing challenge for contract drafting, International Cybersecurity Law Review, 2(1), 161-171"
                    },
                    {
                        "key": "ref5",
                        "unstructured": "Haller, J., & Wallen, C. (2016). Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach, Carnegie Mellon University Software Engineering Institute. Ayoub Alfawzan, Omer Alrwais: Contractual Agreement Aspect of Third-party Risk Management in Information Security"
                    },
                    {
                        "key": "ref6",
                        "unstructured": "Singh, A. (2009). Improving Information Security Risk Management [Unpublished doctoral dissertation]. University of Minnesota"
                    },
                    {
                        "key": "ref7",
                        "doi": "10.2139/ssrn.3763399",
                        "unstructured": "VanHoy, J. (2021). Third Party Risk Management. Available at SSRN 3763399"
                    }
                ],
                "record": {
                    "registrant": "Longman Publishers",
                    "registered": "2025-08-26",
                    "updated": "2026-09-07",
                    "issue_number": 1,
                    "source": "crossref-api",
                    "source_agency": "Crossref (member 25296)"
                }
            },
            "url_after": "https://jst.org.in/index.php/pub/article/view/1332",
            "sha256_before": null,
            "sha256_after": "7a0de009f3d6e15eba425aa6d55474acc008ced26c88810de24d0af00f00501d"
        },
        {
            "seq": 2,
            "kind": "update",
            "at": "2026-09-29 23:59:51",
            "by": "Administrator (admin)",
            "by_kind": "user",
            "note": "record re-read from api.crossref.org",
            "changes": [
                {
                    "path": "container.titles.0.value",
                    "from": "Journal of Science &amp; Technology",
                    "to": "Journal of Science & Technology"
                }
            ],
            "record_after": {
                "format": "smartscholars-doi-metadata/1.0",
                "doi": "10.46243/jst.2025.v10.i07.pp01-09",
                "referent": "Creation",
                "type": "JournalArticle",
                "structural_type": "Digital",
                "modes": [
                    "Visual"
                ],
                "characters": [
                    "Language"
                ],
                "titles": [
                    {
                        "value": "Contractual Agreement Aspect of Third-party Risk Management in Information Security",
                        "type": "PrincipalTitle"
                    }
                ],
                "identifiers": [
                    {
                        "type": "DOI",
                        "value": "10.46243/jst.2025.v10.i07.pp01-09"
                    }
                ],
                "agents": [
                    {
                        "role": "author",
                        "name": {
                            "given": "",
                            "family": "Ayoub Alfawzan"
                        },
                        "sequence": "first"
                    },
                    {
                        "role": "author",
                        "name": {
                            "given": "",
                            "family": "Omer Alrwais"
                        },
                        "sequence": "additional"
                    },
                    {
                        "role": "publisher",
                        "name": {
                            "org": "Longman Publishers"
                        }
                    }
                ],
                "dates": {
                    "published": "2025-07-18",
                    "date_type": "PublicationDate",
                    "online": "2025-07-18"
                },
                "container": {
                    "type": "Journal",
                    "titles": [
                        {
                            "value": "Journal of Science & Technology",
                            "type": "PrincipalTitle"
                        },
                        {
                            "value": "J. sci. technol.",
                            "type": "AbbreviatedTitle"
                        }
                    ],
                    "identifiers": [
                        {
                            "type": "ISSN",
                            "value": "2456-5660",
                            "medium": "electronic"
                        }
                    ],
                    "volume": "10",
                    "issue": "7",
                    "pages": {
                        "first": "1",
                        "last": "9"
                    }
                },
                "links": [
                    {
                        "url": "https://jst.org.in/index.php/pub/article/view/1332",
                        "return_type": "text/html",
                        "primary": true
                    },
                    {
                        "url": "https://jst.org.in/index.php/pub/article/download/1332/1008",
                        "purpose": "text-mining",
                        "return_type": "application/pdf"
                    }
                ],
                "abstract": {
                    "value": "Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security."
                },
                "license": {
                    "url": "https://creativecommons.org/licenses/by/4.0",
                    "start": "2025-07-18",
                    "applies_to": "unspecified"
                },
                "references": [
                    {
                        "key": "ref1",
                        "doi": "10.1109/itsim.2008.4631922",
                        "unstructured": "Aris, S. R. H. S., Arshad, N. H., & Mohamed, A. (2008). Conceptual framework on risk management in IT outsourcing projects. management, 36(37), 37-38"
                    },
                    {
                        "key": "ref2",
                        "doi": "10.1080/1097198x.2021.1993725",
                        "unstructured": "Bhatti, B. M., Mubarak, S., & Nagalingam, S. (2021). Information security risk management in it outsourcing–a quarter-century systematic literature review. Journal of Global Information Technology Management, 24(4), 259-298"
                    },
                    {
                        "key": "ref3",
                        "unstructured": "Boggavarapu, S. (2021). The Effect of Third-Party Service Providers on Information Security Breaches at Financial Institutions (Doctoral dissertation, University of the Cumberlands)"
                    },
                    {
                        "key": "ref4",
                        "doi": "10.1365/s43439-021-00029-4",
                        "unstructured": "Bomhard, D., & Daum, A. (2021). Cybersecurity in outsourcing and cloud computing: a growing challenge for contract drafting, International Cybersecurity Law Review, 2(1), 161-171"
                    },
                    {
                        "key": "ref5",
                        "unstructured": "Haller, J., & Wallen, C. (2016). Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach, Carnegie Mellon University Software Engineering Institute. Ayoub Alfawzan, Omer Alrwais: Contractual Agreement Aspect of Third-party Risk Management in Information Security"
                    },
                    {
                        "key": "ref6",
                        "unstructured": "Singh, A. (2009). Improving Information Security Risk Management [Unpublished doctoral dissertation]. University of Minnesota"
                    },
                    {
                        "key": "ref7",
                        "doi": "10.2139/ssrn.3763399",
                        "unstructured": "VanHoy, J. (2021). Third Party Risk Management. Available at SSRN 3763399"
                    }
                ],
                "record": {
                    "registrant": "Longman Publishers",
                    "registered": "2025-08-26",
                    "updated": "2026-09-07",
                    "issue_number": 1,
                    "source": "crossref-api",
                    "source_agency": "Crossref (member 25296)"
                }
            },
            "url_after": "https://jst.org.in/index.php/pub/article/view/1332",
            "sha256_before": "7a0de009f3d6e15eba425aa6d55474acc008ced26c88810de24d0af00f00501d",
            "sha256_after": "537ab14b392c710d0c54385d5a4f579d05c19af36cc72ed8b815d3cb69f81729"
        }
    ]
}