Excel Formula

profilejohn_promo
ITRMSRMAssessmentsRUBRIC_Update_2.1.24.xlsm

Step 1 - Pre-Assessment

IT Risk Advisory 3rd Party Risk Pre-Assessment Rubric
ITRA Team Member Completing This Assessment and Date: Vendor Name:
SRM Assessor: Division:
New/Periodic: Description (from IRA):
All Available Documents have Been Downloaded From the Tool and Stored: SRM/IRA Reference
Peer Review:
Existing Findings/Notes
Finding/ Requirement # Finding/Requirement Existing Ranking Description Risk Statement Recommendation ITRA Update

Step 2 - Assessment Info

IT Risk Advisory 3rd Party Risk Assessment Rubric
FIELD RESPONSE ITRA NOTES/FINDINGS
Vendor Name:
Data Classification:
Data Elements Accessed/Processed/Stored:
Data Storage/Access Method:
Data Flow Diagrams Provided:
Data Flow Diagram Comments:
Subservice Organizations:
Subservice Organization List:
Offshoring:
IRA RISK DOMAINS IN SCOPE RISK DOMAIN RANKING
Information Risk N/A
Technology Risk N/A
Operational Resiliency N/A
Legal & Compliance Risk N/A
Third Party Risk N/A
Reporting Risk N/A
TIG Risk N/A
Model Risk N/A
Financial Crimes Risk N/A
People Risk N/A
Supplier Engagement Inherent Risk Rating

Step 3 - Controls Checklist

# Control Group/ Policy TSC Risk Domain FM Policy/ Standard # FM Control Control Requirement Policy/ Directive Verbiage Status Vendor Policy Name in Folder Verbiage or TSC Covering Control (If applicable) Remarks
1 SOC 2 Type II Information Risk IT Third Party SOP SOC 2 Type 2 report provided from within the past 12 months with a period of performance of 12 months (or sufficient bridge letter) OR valid ISO 27001 with a Statement of Applicability and Area of Nonconformities included. Policy has not been reviewed since May 2022* In addition to the required assessments through the SRM Procedures, ITRM-TP will perform additional assessments as deemed necessary. Any documentation provided outside of periodic vendor risk assessments to Contract Owners to evidence the confidentiality, availability, and integrity of a supplier’s controls (SOC 2 Type II reports, etc.) should be sent to ITRM-TP for review. Additionally, ITRM-TP will assess EO+T suppliers which may not have triggered an assessment based on the completion of the IRA or which may not have an ongoing assessment done on annual basis. The ITRM-TP assessment will include (at the least) a review of the supplier’s SOC 2 Type II reports.
2 SOC 2 Type II Information Risk IT Third Party SOP SOC 2 Type 2 report includes Confidentiality if data classification is above confidential and availability if OR Risk is in scope No requirement for SOC 2 to cover any specific trust prinicples based on data access level
3 SOC 2 Type II Information Risk IT Third Party SOP All deviations contain valid management responses
4 Internal Vulnerability Scan Information Risk D.SEC.GRC.5.1 Information Security Directives Internal vulnerability Scan provided or SOC 2 Type II control verifying that internal vulnerability scans occur on a minimum of a quarterly frequency with all vulnerabilities tracked to closure. On a monthly frequency at minimum, Technology Assets must be scanned for known vulnerabilities and system security misconfigurations. Scans must be authenticated where technically feasible.
5 Internal Vulnerability Scan Information Risk D.SEC.GRC.5.1 Information Security Directives Internal Vulnerability Scan is dated within past three months On a monthly frequency at minimum, Technology Assets must be scanned for known vulnerabilities and system security misconfigurations. Scans must be authenticated where technically feasible.
6 Internal Vulnerability Scan Information Risk D.SEC.GRC.5.3 D.SEC.GRC.5.7 Information Security Directives Vulnerability Scan contains a remediation plan or status of any medium or higher risk vulnerabilities identified D.SEC.GRC.5.3: Severity of vulnerabilities detected during application security testing, infrastructure vulnerability scans and penetration testing must include a rating system, based on industry standard methodologies such as the Common Vulnerability Scoring System (CVSS), and/or Open Web Application Security Project (OWASP), as applied to Freddie Mac’s environment. D.SEC.GRC.5.7: Vulnerabilities identified during Infrastructure scans, penetration testing, and application security testing are required to be remediated based on severity and the following application classification within enterprise application repository ( for e.g., Technology Portfolio Insights): Emergency - 14, Critical, 30, High - 90, Medium - 180, Low - 365
7 External Penetration Test Information Risk D.SEC.SE.4.2 Information Security Directives External penetration test provided or SOC 2 Type II control present verifying that external penetration tests occur at a minimum of an annual frequency with all findings tracked to closure. Information Security must report results from third-party external penetration testing exercises, along with status of the remediating actions to address any deficiency, to Freddie Mac's Internal Regulatory Affairs and applicable stakeholder on a quarterly basis.
8 External Penetration Test Information Risk D.SEC.SE.4.2 Information Security Directives External penetration test is dated within the past 12 months Information Security must report results from third-party external penetration testing exercises, along with status of the remediating actions to address any deficiency, to Freddie Mac's Internal Regulatory Affairs and applicable stakeholder on a quarterly basis.
9 External Penetration Test Information Risk D.SEC.GRC.5.3 D.SEC.GRC.5.7 Information Security Directives External penetration test contains a remediation plan or status of any medium or higher risk vulnerabilities identified D.SEC.GRC.5.3: Severity of vulnerabilities detected during application security testing, infrastructure vulnerability scans and penetration testing must include a rating system, based on industry standard methodologies such as the Common Vulnerability Scoring System (CVSS), and/or Open Web Application Security Project (OWASP), as applied to Freddie Mac’s environment. D.SEC.GRC.5.7: Vulnerabilities identified during Infrastructure scans, penetration testing, and application security testing are required to be remediated based on severity and the following application classification within enterprise application repository ( for e.g., Technology Portfolio Insights): Emergency - 14, Critical, 30, High - 90, Medium - 180, Low - 365
10 Background check policy Information Risk Policy 3-227 Background Checks Policy Criminal Background checks are performed for all new employees prior to gaining access to systems All external applicants offered employment with Freddie Mac for non-officer positions must undergo an initial comprehensive background check which includes, but is not limited to, a criminal records check; social security number, education, employment, social media screen and professional references verifications; and a drugtest. All external applicants offered employment in officer positions must undergo an initial comprehensive background check Nothing about system access
11 Code of Conduct/Ethics Information Risk Freddie Mac Code of Conduct A Code of Conduct is in place and available to all employees Code of conduct available on Homefront and renewed every 12 months
12 Security Awareness Training Information Risk D.SEC.GRC.6.1 D.SEC.GRC.6.2 Information Security Directives Security awareness training is required at hire and annually thereafter D.SEC.GRC.6.1: Corporate Policy 6-300 Acceptable Use and Management of End User Technology must be acknowledged by personnel prior to accessing Freddie Mac Technology Assets. (I reviewed policy and it only states that personnell must comply with various information security policies, nothing about training before access) D.SEC.GRC.6.2: Information Security must provide role-based security training to personnel with assigned security roles and responsibilities. Users who are in a role that is required to receive training must complete the applicable role-based training prior to or within 30 days of transfer and annually thereafter. (I believe the word "transfer" can also be interpreted as "hire)
13 Access Management policies Information Risk D.SEC.AC.3.1 Information Security Directive Access is approved prior to being granted The creation, disablement, update, or deletion of Entitlements that provide access to Freddie Mac technology assets must be executed using an Information Security approved identity and account management process and system.
14 Access Management policies CC.62 Information Risk D.SEC.AC.1.2 Information Security Directives System access is removed in a timely manner following termination (under 24 hours) Requests for termination of an employee or contingent worker’s (CW) access (i.e., Network, Active Directory, VPN and wireless) must be initiated by the employee or CW’s manager within timelines defined by Human Resources or Contingent Worker Operations. For automated deprovisioning platforms, revocation must be completed within one business day of termination day. For manual deprovisioning platforms, revocation must be completed within two business days of termination day.
15 Access Management policies Information Risk D.SEC.AC.3.3 Information Security Directives General user access is reviewed semi-annually Entitlement owners or Identity sponsors22 must certify identity’s access to Entitlement for application as per the frequency below: Access Criticality Application Types23 Frequency/ Access Limit Privileged -- Certified quarterly Elevated -- Timebound to 6 months or certified semi-annually
16 Access Management policies Information Risk D.SEC.AC.3.3 Information Security Directives Privileged user access is reviewed quarterly Entitlement owners or Identity sponsors22 must certify identity’s access to Entitlement for application as per the frequency below: Access Criticality Application Types23 Frequency/ Access Limit Privileged -- Certified quarterly Elevated -- Timebound to 6 months or certified semi-annually
17 Access Management policies Information Risk D.SEC.AC.1.4 Information Security Directives Use of shared accounts is tracked, secured, or vaulted Identity Sponsor must maintain metadata associated with non-human and shared accounts including description, asset affiliation, lifecycle status within enterprise identity management system (“IDMS”). Note: Account profiles managed by Freddie Mac personnel or reside on Freddie Mac hosted assets are considered in scope to be managed within enterprise IDMS
18 Password Management Information Risk D.SEC.AC.4.3 Information Security Directives Minimum of 8 characters password length Passwords for other internal accounts and external accounts must be at least 8 characters long and meet at least three (3) of the five (5) complexity requirements: • One uppercase alphabetic character • One lowercase alphabetic character • Minimum of one number and one symbol • Must not contain three or more consecutive characters from the corresponding account name • Must not contain three (3) repeated characters
19 Password Management Information Risk D.SEC.AC.4.6 Information Security Directives IT Third Party SOP Passwords must be changed every 90 days if the password length is 8 characters Passwords must be changed annually if password length is 12 characters or longer Passwords must be changed annually if MFA is used Passwords for accounts must be changed as follows: • 90 days for production accounts • 180 days for non-production accounts • 365 days for accounts assigned to external system accounts • 90 days for external human accounts If a password is believed to be compromised; it must be changed immediately.
20 Password Management Information Risk D.SEC.AC.4.4 Information Security Directives Updated passwords must not be the same as any of the previous 6 (six) passwords used. Updated passwords must not be the same as any of the previous ten (10) passwords used.
21 Password Management Information Risk D.SEC.AC.2.5 Information Security Directives Requirements are in place for lockout after five (5) invalid login attempts and log for invalid logins Human accounts (for Internal, External and Consumer identities) must be locked out after a maximum of five (5) consecutive failed login attempts within a 30-minute period. The account must be locked out for a duration of 30 minutes from the last failed login or until it is reset by an authorized administrator or through an approved self-service capability.
22 Password Management CC7.1, CC8.1 Information Risk D.SEC.AC.2.3 Information Security Directives Requirements are in place for lockout after inactivity. (60 minutes) Human account interactive (for internal, external and consumer identities) sessions must be terminated after a maximum of 60 minutes of inactivity, and immediately after the user logs off the system/application. Notifications (or clear indication) of session termination must be displayed upon terminating the interactive session.
23 Data Encryption policy Information Risk D.SEC.SE.1.1 Information Security Directives S11-113.D Cybersecurity Standard Data at rest is encrypted with a minimum of AES-256 encryption 7.6.3: Encrypt data at-rest to prevent data from being misused or read by unauthorized users. Applied Cryptography Encryption Standards contain FRE requirements
24 Data Encryption policy Information Risk D.SEC.SE.3.12 Information Security Directives S11-113.D Cybersecurity Standard Data in transit if encrypted with tls v1.2 or higher encryption 7.6.2: Encrypt data in-transit to achieve the following objectives: • Prevent the data from being read by unauthorized users; • Enable the data’s recipient to authenticate the sender’s identity; and • Detect whether the data was altered in transit. Applied Cryptography Encryption Standards contain FRE requirements
25 System Hardening guidelines Information Risk D.SEC.AC.4.2 Information Security Directives Default passwords must be changed upon initial login Password reset for newly provisioned and temporary password(s) must be unique for each user and meet complexity requirements. Temporary passwords must be set to change upon initial login
26 System Hardening guidelines Information Risk D.SEC.SE.2.7 Information Security Directives Hardening standards include disabling, closing, or removing unnecessary network ports Information security must protect End User Technology from possible exploitation or data exfiltration by managing/blocking USB ports and local network access.
27 Patch Management Information Risk D.SEC.GRC.5.7 Information Security Directives Patch management timelines are in place (includes servers, databases, end points, and software): Critical patches applied within 30 days, high within 90 days, medium within 180 days. Vulnerabilities identified during Infrastructure scans, penetration testing, and application security testing are required to be remediated based on severity and the following application classification within enterprise application repository ( for e.g., Technology Portfolio Insights): Vulnerability Type Severity Remediation Timeline (days) All Vulnerability Scans Incl: Infrastructure Application Security Testing (SAST, DAST, FOSS) Penetration Testing Emergency 14 Critical 30 High 90 Medium 180 For Penetration Testing only Low 365 For vulnerabilities other than from Penetration Testing identified as a Low severity rating remediation timeline is based on business discretion.
28 Electronic/Physical Data Destruction Policy/Procedure Information Risk 7-710 Policy on Document Lifecycle and Legal Holds Requirements for adhering to a data retention schedule Section III: Managing Records and the Document Lifecylce
29 Data Loss Prevention policy (If Restricted-PPI) Information Risk D.SEC.GRC.7.2 Information Security Directives Mechanisms must be in place to detect and/or prevent the exfiltration of Corporate Information as per the Enterprise DLP program scope. D.SEC.GRC.7.2 Mechanisms must be in place to detect and/or prevent the exfiltration of Corporate Information as per the Enterprise DLP program scope.
30 Physical & Environmental Security Information Risk 5-300 Corporate Security Policy Badge access is in place to all corporate facilities All individuals entering a Freddie Mac facility must comply with security and identification protocols, including the use of biometric devices", security identification (badges), and a unique personal identification number (PIN) selected by the individual.
31 Physical & Environmental Security Information Risk 5-300 Corporate Security Policy IT Third Party SOP CCTV cameras are required in entry and exit points of corporate facilities and footage is required to be retained for a minimum of 30 days
32 Physical & Environmental Security Information Risk HomeFront/ Host & Visitors Visitors to corporate facilities are required to sign in, provide ID, and be escorted All visitors must: Be preregistered by a Freddie Mac host. Check in at the main reception desk and with building security, if applicable. Provide a valid, government-issued photo ID.
33 Incident Management Information Risk S11-101.B Issue Management Standard Process in place from event detection through reporting/remediation The issue management standard lays out the scope which includes: - Issue Identification and Recording - Issue Severity Determination - Issue Remediation - Issue Monitoring and Reporting - Issue Downgrade and Closure
34 Incident Management Information Risk D.SEC.CS.1 Information Security Directives Method in place for monitoring threats or incidents D.SEC.CS.1: Security Event Monitoring lays out how Security Events shall be monitored via audit logs. Section D.SEC.CS.1.1 requires that Infrastructure/System Security audit logging records shall be sent to a centralized log repository for review and analysis.
35 Incident Management Information Risk S11-202.D Incident Response Standard Response protocols or individuals in charge for responding are in place and documented Section 3: Roles and Responsibilities: • The Executive Vice President – Enterprise Operations and Technology (“EVP-EOT”) in the Enterprise Operations and Technology (“EOT”) Division, or his or her delegate, is responsible for developing and maintaining an IR plan to prepare for and manage technology and information security related incidents and notifying/escalating to the Crisis Management Team – Executive (“CMT-E”) for IT incidents that meet the escalation criteria defined in the Crisis Management Plan. • The Chief Data Officer (“CDO”) in the EOT Division is responsible for developing and maintaining an IR plan to prepare to guide participation in the response to data privacy breaches and notifying/escalating to the CMT-E for privacy incidents that meet escalation criteria defined in the Crisis Management Plan. • The VP-Enterprise Services in the Chief Administrative Officer Division is responsible for developing and maintaining an IR plan to prepare for and manage incidents related to physical facilities and the life and safety of personnel, and notifying/escalating to the CMT-E for facility, security, life, and safety incidents that meet escalation criteria defined in the Crisis Management Plan.
36 Incident Management Information Risk D.SEC.CS.2.10 Information Security Directives Individual or team responsible for performing forensic analysis is documented D.SEC.CS.2.7: Information Security must document information pertaining to all incidents for future reviews. This may include maintenance records, status, analysis reports of evidence gathered during forensics, in accordance with Record and Information Management schedule. D.SEC.CS.2.10: Analysis of forensic evidence and final reports from a cybersecurity incident are reported to all authorized parties and dispositioned per the documented incident response process.
37 Incident Management Information Risk S11-202.A Crisis Management Standard Process in place to notify customers of an incident in timely manner The CM plan must: Contain the list and contact information of key internal and external stakeholders who may have a role in responding to, or must be notified of, a crisis
38 Incident Management Information Risk S11-202.A Crisis Management Standard Communication plans are in place for incidents The CM plan must: Establish criteria and protocols for communications and escalations to relevant internal stakeholders, Establish criteria and protocols for communication to external parties, such as the Federal Housing Finance Agency, law enforcement agencies, other governmental organizations, vendors, customers, investors and the media7
39 Incident Management Information Risk D.SEC.CS.2.7 & D.SEC.CS.2.8 Information Security Directives Process for reporting and logging incidents D.SEC.CS.2.7 Information Security must document information pertaining to all incidents for future reviews. This may include maintenance records, status, analysis reports of evidence gathered during forensics, in accordance with Record and Information Management schedule. D.SEC.CS.2.8 Information Security must have a capability to allow Freddie Mac Personnel to report suspected events and triage them for further analysis or escalation.
40 Incident Management Information Risk S11-109.D Root Cause Analysis Standard Process for performing a root cause analysis Section: III. Root Cause Analysis
41 Business Continuity Plan Operational Resiliency S11-202.B Business Continuity Management Standard Requirement for performing a business impact analysis annually BIAs and BCPs must be reviewed, updated, and approved by their respective DROs on a rolling 12-month cycle, or more frequently if significant changes occur that could impact the plan’s effectiveness.
42 Business Continuity Plan Operational Resiliency S11-202.B Business Continuity Management Standard Roles and responsibilities are defined in the BCP Include the roles, responsibilities, and contact information of key internal and third party stakeholders who may be involved in recovery efforts.
43 Business Continuity Plan Operational Resiliency S11-202.B Business Continuity Management Standard Process for addressing loss of people, loss of technology, loss of location, etc Disaster Recovery Plans are required to: • Identify technology and information assets (both internal and third party) and their dependencies that support relevant business functions • Identify applicable recovery criteria for assets and services contained in the plan
44 Disaster Recovery Plan Operational Resiliency S11-202.B Business Continuity Management Standard Roles and responsibilities are defined in the Disaster Recovery Plan V. Disaster Recovery: DRPs, testing, and plan maintenance are required for all IT assets and services. DRPs define the procedures and resources required to restore services following a disruption. Disaster Recovery Plans are required to: • Include the roles, responsibilities, and contact information of key internal and third party stakeholders who may be involved in recovery efforts
45 Disaster Recovery Plan Operational Resiliency S11-202.B Business Continuity Management Standard A process to be followed in the event of a disaster is defined Disaster Recovery Plans are required to: • Include the sequence in which technology and information assets should be recovered • Identify applicable recovery criteria for assets and services contained in the plan
46 Disaster Recovery Plan Operational Resiliency S11-202.B Business Continuity Management Standard Communication plans are in place in the disaster recovery plan Disaster Recovery Plans are required to: Define communication needs and pathways not covered by communication protocols in the BCPs and the Crisis Management Plan5
47 Disaster Recovery Plan Operational Resiliency S11-202.C Disaster Recovery Testing Standard Requirement for testing the disaster recovery plan annually DRPs must be tested annually
48 Disaster Recovery Plan Operational Resiliency S11-202.C Disaster Recovery Testing Standard Requirement to perform lessons learned and update plan when necessary Testing Requirement: Analyze lessons learned to identify opportunities to enhance technology availability, recovery capabilities, and testing
49 Disaster Recovery Plan Operational Resiliency S11-202.B Business Continuity Management Standard RTOs/RPO for systems and infrastructure supporting FRE services are in place Business-expressed process recovery time objectives and recovery point objectives
50 Disaster Recovery Plan Operational Resiliency S11-202.B Business Continuity Management Standard Identification of third party dependencies (utilities, service providers, etc) Disaster Recovery Plans are required to: Identify technology and information assets (both internal and third party) and their dependencies that support relevant business functions
51 Disaster Recovery Test Operational Resiliency S11-202.C Disaster Recovery Testing Standard Disaster Recovery Test dated within the past 12 months with test scope and results defined IV. Testing Requirements • DRPs must be tested annually; each test plan must include: - Test scope, objectives, and schedule - A test scenario used to identify the scope, severity, and duration of the simulated disruption - Testing roles and responsibilities of plan stakeholders - Test procedures designed to evaluate the preparedness of the organization to respond to technology disruptions and achieve recovery objectives - Requirements for documenting test results
52 Information Security Policy/ Backup Policy Operational Resiliency D.SEC.SE.1.2 Information Security Directives Backups are encrypted Freddie Mac’s Corporate Information and data when at-rest must be encrypted as per Cybersecurity Standard’s (S11–113.D) Applicable Standard of Care.
53 Third Party Risk Management Policy Third Party Risk 11-225 Third Party Risk Policy Process in place to evaluate third parties based on risk prior to signing a contract This Policy establishes the Life Cycle, Third Party types, scope, roles and responsibilities and governance requirements. The Related Standards further define responsibilities and minimum mitigating controls and requirements for managing the risks of each Third Party type across the Life Cycle, which consists of the following five stages: - Risk Assessment - Due Dilligence in Third Party Provider Selection - Contract Negotiation - Ongoing Monitoring - Termination
54 Third Party Risk Management Policy Third Party Risk 11-225 Third Party Risk Policy Process in place to evaluate third parties' information security practices on an ongoing basis This Policy establishes the Life Cycle, Third Party types, scope, roles and responsibilities and governance requirements. The Related Standards further define responsibilities and minimum mitigating controls and requirements for managing the risks of each Third Party type across the Life Cycle, which consists of the following five stages: - Risk Assessment - Due Dilligence in Third Party Provider Selection - Contract Negotiation - Ongoing Monitoring - Termination
55 Change Management/ SDLC Technology Risk S11-132.E Software Development Standard Requirement for approval prior to implementing changes into production All activities of the requirements process must be organized in an enterprise-approved system that provides detailed requirement traceability and control capabilities and is compliant with the Identity and Access Management Standard.
56 SDLC Technology Risk S11-132.E Software Development Standard SDLC includes the end-to-end SDLC process from requesting change to implementing and validating in production S11-132.E: Section: Requirements (Foundational Requirements, Implementation, Develop, Test, Release, and Deploy)
57 SDLC Technology Risk D.SEC.SA.1.6 Information Security Directives Requirement in place for performing a risk assessment on software and applications Non-production services that may traverse into production (or are accessible from production) must be subjected to risk assessment prior to approval by Architecture Review Board4 to confirm the risk to confidentiality, integrity and availability of Corporate Information is considered and understood prior to approval.
58 Technology Risk D.SEC.SA.1.7 Information Security Directives Requirement for restriction of developers accesing the production environment Traffic from designated developer’s endpoint devices (e.g., laptops/desktops) must be physically or logically separated from the production network. If the production network is utilized as transport, access to a non-production environment must only be permitted via the following methods: 1) a point-to-point virtual private network (VPN), 2) virtual desktop (VDI), 3) designated jump-hosts, or another Corporate Information Security approved solution. No direct access from development environments to production environments is authorized unless the non-production environment has equivalent assurances for Confidentiality, Integrity, Availability, and for Change Management, as does production.
59 SDLC Technology Risk D.SEC.SA.2.2 Information Security Directives S11-132.E Software Development Standard Requirement in place for testing code before going into production Freddie Mac Technology Assets (including new applications) that are developed in-house or have in-house developed custom code components must go through Static Application Security Testing (SAST) to identify security vulnerabilities prior to production release. Remediation of findings must be as per the Vulnerability Remediation Timeline requirements stated in these directives., S11-132.E Section: Test
60 SDLC Technology Risk S11-132.E Software Development Standard Requirement to perform peer review over code before going into production Define a peer review process for code and other implementation artifacts.
61 SDLC Technology Risk D.SEC.SA.2.2 Information Security Directives Requirement for static code scanning before going into production Freddie Mac Technology Assets (including new applications) that are developed in-house or have in-house developed custom code components must go through Static Application Security Testing (SAST) to identify security vulnerabilities prior to production release.
62 Cloud Security/ Cyptology Policy Technology Risk D.SEC.SE.1.1 Inormation Security Directives Sufficient cloud security controls are in place including key management practices D.SEC.SE.1.1 Information Security must identify applicable cryptographic protocols, algorithms, key sizes, key storage, data at rest usage patterns. A schedule for deprecated cryptographic components must be published, to help ensure Freddie Mac Technology Assets remain in compliance. All internal, external services and technology associated with the management of keys used to protect Corporate Information must be developed and maintained in alignment with relevant Cryptographic directives.

Step 4 - Consolidated Findings

IT Risk Advisory 3rd Party Risk Assessment Rubric
Source Document Risk Observation / Description Existing Finding Risk Statement / FRE’s Risk Exposure Related to the Finding Recommendation Level 2 Risk Likelihood Impact Rating
OBSERVATIONS NARRATIVE

Drop Downs

Yes New Restricted PPI Stored Within Freddie Systems w/Remote or Local Access US-Based Vendor - All Products and Services within US Assessment Tool 4.1 People Risk High Almost Certain Extreme No Gap
No Periodic Confidential PPI Transferred to the Vendor US-Based Vendor - Products or Services in Foreign Location Findings Summary 4.2 Reporting Risk Medium Likely Substantial Partial Gap
N/A Periodic w/Service Changes Restricted Hosted by Vendor Foreign Vendor - Products or Services in Foreign Location Other 4.3 TIG Risk Low Possible Moderate Full Gap
Renewal with net new risk domain(s) Confidential Hosted by Other Provider Policies / Procedures 4.4 Information Risk Observation Unlikely Limited Could Not Verify
Non-Public N/A 4.5 Technology Risk Monitor Remote Negligible N/A
Public 4.6 Third Party Risk
No Access to FRE Data 4.7 Operational Resiliency Risk
4.8 Model Risk
4.9 Fraud Risk
4.10 Legal and Compliance Risk

Automation

Automation Idea Example
Color-coding based on answers If "SOC 2 Provided" is "No," turn the cell RED
Automated risk statements based on certain selections If "SOC 2 Provided" is "No," automatically populate a finding based on generic language

image1.png

image2.png