Cite this DOI
10.46243/jst.2025.v10.i07.pp01-09 · Contractual Agreement Aspect of Third-party Risk Management in Information Security
APA (7th edition)
Ayoub Alfawzan, & Omer Alrwais (2025). Contractual Agreement Aspect of Third-party Risk Management in Information Security. *Journal of Science & Technology*, *10*(7), 1–9. https://doi.org/10.46243/jst.2025.v10.i07.pp01-09
⬇ text Italics are shown as *asterisks* in plain text — the journal or book title and the volume.
BibTeX
@article{ayoubalfawzan2025contractual,
author = {Ayoub Alfawzan and Omer Alrwais},
title = {{Contractual Agreement Aspect of Third-party Risk Management in Information Security}},
journal = {Journal of Science \& Technology},
year = {2025},
month = {jul},
volume = {10},
number = {7},
pages = {1--9},
publisher = {Longman Publishers},
issn = {2456-5660},
doi = {10.46243/jst.2025.v10.i07.pp01-09},
url = {https://doi.org/10.46243/jst.2025.v10.i07.pp01-09},
abstract = {Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security.}
}RIS (EndNote, Zotero, Mendeley)
TY - JOUR TI - Contractual Agreement Aspect of Third-party Risk Management in Information Security AU - Ayoub Alfawzan AU - Omer Alrwais JO - Journal of Science & Technology PY - 2025 DA - 2025/07/18/ VL - 10 IS - 7 SP - 1 EP - 9 PB - Longman Publishers SN - 2456-5660 AB - Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security. DO - 10.46243/jst.2025.v10.i07.pp01-09 UR - https://doi.org/10.46243/jst.2025.v10.i07.pp01-09 ER -
CSL-JSON
{
"type": "article-journal",
"id": "10.46243/jst.2025.v10.i07.pp01-09",
"DOI": "10.46243/jst.2025.v10.i07.pp01-09",
"URL": "https://doi.org/10.46243/jst.2025.v10.i07.pp01-09",
"title": "Contractual Agreement Aspect of Third-party Risk Management in Information Security",
"source": "Smart Scholars DOI Registry",
"container-title": "Journal of Science & Technology",
"author": [
{
"family": "Ayoub Alfawzan"
},
{
"family": "Omer Alrwais"
}
],
"issued": {
"date-parts": [
[
2025,
7,
18
]
]
},
"volume": "10",
"issue": "7",
"page": "1-9",
"publisher": "Longman Publishers",
"abstract": "Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security.",
"ISSN": "2456-5660"
} ⬇ .json What citeproc and reference managers read; the DOI system hands it out for Accept: application/vnd.citationstyles.csl+json, and so does this registry's resolver.
From the record as registered (version 2) — the record and its history. Programs: https://registry.smartscholars.in/api.php?action=cite&doi=10.46243%2Fjst.2025.v10.i07.pp01-09 gives all four in one JSON answer.
