揭示第三方安全风险如何通过信任传递影响客户责任,提出治理新框架。
Fortress and Gatekeeper: Theorizing Transitive Trust in Third-Party Cybersecurity Risk Governance
- 用信任传递理论分析供应商安全事件对主服务方的连带影响。
- 提出'堡垒与守门人'框架,以数据流和信任界定安全边界。
- 适合关注供应链安全、合规治理与合同设计的研究者和从业者。
第三方供应商(如分析平台、云服务商、身份认证提供方和软件供应商)日益嵌入数字服务交付中。尽管这种合作带来规模效应与专业化优势,但也使客户数据和安全实践进入客户难以看见、选择或评估的环境。本文通过分析2025年11月OpenAI-Mixpanel安全事件的公开文档,探讨此类问题:供应商环境中的安全事件如何演变为焦点组织的治理与问责难题。基于组织信任研究与代理理论,本文认为第三方网络安全风险既是信任关系,也是委托管理问题。客户信任可见的服务提供方,而该提供方依赖于安全实践部分透明且不可控的供应商。本文提出‘转置信任’概念,即客户对数字服务的信任取决于服务方授权供应商的安全实践。进而构建‘堡垒与守门人’框架,强调安全治理边界应由信任关系与数据流动决定,而非仅凭正式组织所有权。分析提炼出四个命题:供应商集成、元数据暴露、供应商保证、数据扩散。研究贡献在于阐明委托数据处理如何引发客户层面的责任,并为供应商分级、数据分类、合同设计、持续保障与数据最小化提供启示。
原文摘要 · Abstract (English)
Third-party vendors, such as analytics platforms, cloud services, identity providers, and software suppliers, are increasingly embedded in digital service delivery. While these arrangements enable scale and specialization, they also move customer data and security-relevant practices into environments that customers rarely see, select, or evaluate. This paper examines this problem through a document analysis of the November 2025 OpenAI-Mixpanel security incident. The incident serves as an illustrative case for showing how a security event in a vendor environment can become a governance and accountability problem for the focal organization that maintains the customer relationship. Drawing on organizational trust research and agency theory, the paper argues that third-party cybersecurity risk is both a trust relationship and a delegation problem. Customers trust the visible service provider, while the provider relies on vendors whose security practices are only partially visible and controllable. The paper develops the concept of transitive trust, where customer trust in a digital service depends on the security practices of vendors authorized by that service provider. It then presents the Fortress and Gatekeeper framework, which explains cybersecurity governance boundaries through trust and data flows rather than formal organizational ownership alone. The analysis develops four propositions concerning vendor integration, metadata exposure, vendor assurance, and data proliferation. The paper contributes to cybersecurity governance scholarship by explaining how delegated data processing creates customer-facing accountability and by identifying implications for vendor tiering, data classification, contractual design, continuous assurance, and data minimization.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。