Smart Scholars🛡 Scholar Shield🏛 Research Integrity Desk🧩 Portfolio Console📰 Journals🔧 DOI MembersTools🔎 Journal AuditGI GetIndexedDr DOI Doctor

Cite this DOI

10.46243/jst.2025.v10.i07.pp01-09 · Contractual Agreement Aspect of Third-party Risk Management in Information Security

APA (7th edition)

Ayoub Alfawzan, & Omer Alrwais (2025). Contractual Agreement Aspect of Third-party Risk Management in Information Security. *Journal of Science & Technology*, *10*(7), 1–9. https://doi.org/10.46243/jst.2025.v10.i07.pp01-09

⬇ text Italics are shown as *asterisks* in plain text — the journal or book title and the volume.

BibTeX

@article{ayoubalfawzan2025contractual,
  author    = {Ayoub Alfawzan and Omer Alrwais},
  title     = {{Contractual Agreement Aspect of Third-party Risk Management in Information Security}},
  journal   = {Journal of Science \& Technology},
  year      = {2025},
  month     = {jul},
  volume    = {10},
  number    = {7},
  pages     = {1--9},
  publisher = {Longman Publishers},
  issn      = {2456-5660},
  doi       = {10.46243/jst.2025.v10.i07.pp01-09},
  url       = {https://doi.org/10.46243/jst.2025.v10.i07.pp01-09},
  abstract  = {Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security.}
}

⬇ .bib

RIS (EndNote, Zotero, Mendeley)

TY  - JOUR
TI  - Contractual Agreement Aspect of Third-party Risk Management in Information Security
AU  - Ayoub Alfawzan
AU  - Omer Alrwais
JO  - Journal of Science & Technology
PY  - 2025
DA  - 2025/07/18/
VL  - 10
IS  - 7
SP  - 1
EP  - 9
PB  - Longman Publishers
SN  - 2456-5660
AB  - Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security.
DO  - 10.46243/jst.2025.v10.i07.pp01-09
UR  - https://doi.org/10.46243/jst.2025.v10.i07.pp01-09
ER  -

⬇ .ris

CSL-JSON

{
    "type": "article-journal",
    "id": "10.46243/jst.2025.v10.i07.pp01-09",
    "DOI": "10.46243/jst.2025.v10.i07.pp01-09",
    "URL": "https://doi.org/10.46243/jst.2025.v10.i07.pp01-09",
    "title": "Contractual Agreement Aspect of Third-party Risk Management in Information Security",
    "source": "Smart Scholars DOI Registry",
    "container-title": "Journal of Science & Technology",
    "author": [
        {
            "family": "Ayoub Alfawzan"
        },
        {
            "family": "Omer Alrwais"
        }
    ],
    "issued": {
        "date-parts": [
            [
                2025,
                7,
                18
            ]
        ]
    },
    "volume": "10",
    "issue": "7",
    "page": "1-9",
    "publisher": "Longman Publishers",
    "abstract": "Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security.",
    "ISSN": "2456-5660"
}

⬇ .json What citeproc and reference managers read; the DOI system hands it out for Accept: application/vnd.citationstyles.csl+json, and so does this registry's resolver.

From the record as registered (version 2) — the record and its history. Programs: https://registry.smartscholars.in/api.php?action=cite&doi=10.46243%2Fjst.2025.v10.i07.pp01-09 gives all four in one JSON answer.

Everything Smart Scholars runsNine sites, one account. A journal starts at the audit; an author starts at Scholar Shield.

For journals & publishers

Start with the audit — it is free, and it is the gate to everything else.

DOI care

Nine services on one journal profile — each previews first and acts only on your approval.

For authors & researchers

Free to use. Nothing you check is shared with the journal.

For institutions, sponsors & DOI operators

Smart Scholars

Mon–Sat, 10:00–19:00 IST. The Ask AI button on every page answers about our services at any hour.

News

Policies

What we can register a DOI for

20 kinds of record, one account, one place. Every one gets a DOI that resolves, metadata that indexes read, and a record that stays correct afterwards.
Journals
  • Journal articles
  • Journal titles
  • Pending publications
  • Peer reviews
  • Preprints & posted content
Books & conferences
  • Books
  • Book chapters
  • Book series
  • Book sets
  • Conference proceedings
  • Proceedings series
  • Conference papers
Other research output
  • Theses & dissertations
  • Reports & working papers
  • Report series
  • Standards
  • Databases
  • Datasets
  • Figures, tables & supplements
Funding
  • Grants & funding awards

Elsewhere

The same company, in the places our publishers already read.
Smart Scholars · Every service on one pageData from OpenAlex (openalex.org), CC0 · Crossref · ISSN Portal · DOAJContact
WhatsApp