Costly and destructive cybersecurity breaches at companies such as Equifax in 2016 and Target in 2013 that exposed the personal data of millions of consumers were traced back to vulnerabilities unknowingly exposed by third-party vendors rather than the company itself, proving that cybersecurity is only as strong as its weakest link.
To help avoid and minimize the impact of such breaches, the American Bar Association Cybersecurity Legal Task Force has released its Vendor Contracting Project: Cybersecurity Checklist, which is available at no charge on the ABA website (www.americanbar.org). The checklist is designed to manage cybersecurity risk when working with third-party vendors – from vendor selection, to contracting and vendor management.
The checklist provides guidance on:
• Conducting a risk management assessment of the proposed vendors, to identify relevant threats to security.
• Reviewing vendor security practices and the ability to follow them.
• The contracting process, including setting expectations, mitigating risk and allocating liability.
The document also includes information on critical elements needed in any security program, whether a vendor or the procuring organization.
- Posted July 31, 2017
- Tweet This | Share on Facebook
American Bar Association checklist offers guidelines to avoid cyber breaches

headlines Ingham County
- MSU Law Moot Court team of two 3L students emerges national champions at First Amendment Competiton in D.C.
- MSU Law captivated by prominent Harvard professor analyzing artificial intelligence
- OWLS Meeting
- Advocate: Former insurance pro studies in Dual JD program
- Man with disabilities settles accessibility lawsuit
headlines National
- This LA lawyer levels up legal protections in the video game industry
- ACLU and BigLaw firm use ‘Orange is the New Black’ in hashtag effort to promote NY jail reform
- Legal champions to receive Spirit of Excellence Award at 2026 ABA Midyear Meeting
- Fake Sullivan & Cromwell entities used by scammers should be dissolved, suit says
- Hackers gained access to ‘small number’ of attorney emails at Williams & Connolly, firm confirms
- Before joining Anderson Kill, judge was accused of rude behavior on bench, retaliatory threats in ethics case