10.46243/jst.2025.v10.i07.pp01-09 registered
Contractual Agreement Aspect of Third-party Risk Management in Information Security
Resolves to https://jst.org.in/index.php/pub/article/view/1332
Held by Longman Publishers (India) · prefix 10.46243 live · DOI address https://doi.org/10.46243/jst.2025.v10.i07.pp01-09
Registered 29 Sep 2026 via crossref · record version 2 · last change 29 Sep 2026, 11:59 PM · record sha256 537ab14b392c710d…
Resolve ⬇ Record (JSON) ⬇ Kernel Metadata Declaration (XML) Compare with Crossref Cite (APA · BibTeX · RIS · CSL)
What the DOI identifies
JournalArticle — an article in a journal · Digital · Visual
Contractual Agreement Aspect of Third-party Risk Management in Information Security (PrincipalTitle)
Published 2025-07-18
Part of Journal of Science & Technology · ISSN 2456-5660 · volume 10 · issue 7 · pages 1–9
Agents
- Ayoub Alfawzan (author)
- Omer Alrwais (author)
- Longman Publishers (publisher)
Identifiers DOI 10.46243/jst.2025.v10.i07.pp01-09
Abstract
Third-party risks are those faced by an organization when incorporating external entities intotheir ecosystem, infrastructure, or supply chains. These external parties may take the form ofvendors, suppliers, partners, contractors, or service providers, all of whom are granted access tointernal data concerning systems, processes, intellectual property, customer information, orinternal communication. Organizations are reliant on outsourcing, subcontracting, and offshoringto support their business, this has amplified the need for effective Third-Party Risk Management(TPRM) frameworks. Although these practices offer operational efficiency, they introduceinherent risks, necessitating a careful approach to information security (IS). This article exploresthe pivotal role of contractual agreements in TPRM, addressing key questions about contractdeficiencies, adaptability to evolving risks, regulatory impacts, and strategies for incentivizingthird-party risk management. Thorough due diligence, collaborative approaches, andsupplementary risk management strategies have been emphasized in the existing literature. Theconceptual framework underscores the detrimental impact of weak contracts, advocatingdynamic risk assessments, adaptable security standards, and communication and collaborationchannels. Addressing variations in laws and regulations is crucial and requires a clear contractualprovisions and language. The study concludes by providing insights into incentivizing thirdparties to adapt risk management practices and off-the-shelf tools and services handling, therebycontributing a comprehensive guide for organizations to manage third-party relationships in thedomain of information security.
System metadata — ISO 26324:2025, Annex B · DOI Handbook 10.1
Each element by the standard's name (Annex B: reference elements, then administrative) and the Handbook's (in grey), read off the record above.
| Element | Value | In the record |
|---|---|---|
| DOI Name DOI name | 10.46243/jst.2025.v10.i07.pp01-09 | doi |
| Referent Type referentType | Creation | referent |
| Referent Sub-Type referentSubType | JournalArticle — an article in a journal | type |
| Referent Name(s) referentName(s) | Contractual Agreement Aspect of Third-party Risk Management in Information Security (PrincipalTitle) | titles |
| Basic Metadata basicMetadata | author: Ayoub Alfawzan author: Omer Alrwais publisher: Longman Publishers published: 2025-07-18 part of: Journal of Science & Technology · ISSN 2456-5660 · vol. 10 · no. 7 · pp. 1–9 form: Digital · Visual · Language | agents, dates, container, language, structural_type, modes, characters |
| Referent Identifier(s) alternateIdentifier(s) | none besides the DOI | identifiers, relations (IsSameAs) |
| Registration Authority registrationAuthorityCode | Crossref — issued by Crossref (member 25296); held here as a copy | record.source_agency (our code, ra_doi_name, for names issued here once appointed) |
| Created Date issueDate | 2025-08-26 | record.registered (when the DOI name was first registered) |
| relatedIdentifiers | none needed — the descriptive metadata is in this record | container, relations (only where the descriptive metadata lives at another identifier) |
complete Every System Metadata element is here, with the basic metadata a journal article needs.
Recommended for a journal article and not in this record: the language of the content.
The System Metadata Declaration (JSON) · the Kernel Metadata Declaration (XML) · what each sub-type needs
History — the ledger
Every change to this DOI, in order, as it was recorded. Entries are only ever added, never changed or removed.
| # | When | What | By | Changes |
|---|---|---|---|---|
| 1 | 29 Sep 2026, 10:00 PM | register registered at Crossref; record read from api.crossref.org | Administrator (admin) | 70 fields set · sha256 7a0de009f3d6… |
| 2 | 29 Sep 2026, 11:59 PM | update record re-read from api.crossref.org | Administrator (admin) | container.titles.0.value: |
Machine-readable: the history as JSON, with the full record after each change.
