Gizmodo is reporting that “thousands of files containing the personal information and expertise of Americans with classified and up to Top Secret security clearances have been exposed by an unsecured Amazon server, potentially for most of the year.”
“The files have been traced back to TigerSwan, a North Carolina-based private security firm. But in a statement on Saturday, TigerSwan implicated TalentPen, a third-party vendor apparently used by the firm to process new job applicants.”
This points to the need for strong third party vendor management. How is your vendor risk assessment program, and do your need a review to ensure compliance?
http://www.stumbleupon.com/su/1eIONR/:1+6vAnVj:5VHr_L2N/gizmodo.com/thousands-of-job-applicants-citing-top-secret-us-govern-1798733354