Third-Party Risk Management in API-Driven Ecosystems: Continuous Vendor Security Practices and Emerging Challenges
Downloads
Background: APIs are crucial for the digital transformation process due to the integration capabilities provided by them. Nevertheless, greater dependence on outside services has increased the number of potential cybersecurity threats, which makes the problem of third-party risk management one of the top priorities in organizations. The purpose of this study is to identify current continuous vendor security approaches and security challenges that arise in the environment of APIs. Methods: Quantitative cross-sectional research method was applied in the current study. Online questionnaire survey was administered to the US professionals, where 185 questionnaires were distributed, and 165 valid responses were received. Results: The highest mean was obtained in Third Party Risk Management Effectiveness (4.15), while Real Time API Monitoring received the second highest mean (4.12). Real Time API Monitoring also received the highest positive response (74.5%) showing its significance in the process of continuous security management. Limited Vendor Transparency (18.2%) became the main challenge in terms of third-party security risks. Correlation analysis showed the presence of strong positive correlations among all variables studied; the highest correlation was obtained for Real Time API Monitoring and Third-Party Risk Management Effectiveness (r = 0.756), which proves that more monitoring leads to better risk management. Conclusion: The results show the significance of vendor continuous security practices, real-time API monitoring and compliance management in the process of third-party risk management.
[1] A. Brown, J. Fishenden, and M. Thompson, “API economy, ecosystems and engagement models,” in Palgrave Macmillan UK eBooks, pp. 225–236, 2014, doi: 10.1057/9781137443649_13.
[2] S. Dalmolen, H. Moonen, and J. Van Hillegersberg, “Building a supply chain ecosystem: How the Enterprise Connectivity Interface (ECI) will enable and support interorganisational collaboration,” Lecture Notes in Business Information Processing, pp. 228–239, 2015, doi: 10.1007/978-3-319-26739-5_13.
[3] D. Ahlers, L. W. M. Wienhofen, S. A. Petersen, and M. Anvaari, “A smart city ecosystem enabling open innovation,” Communications in Computer and Information Science, pp. 109–122, 2019, doi: 10.1007/978-3-030-22482-0_9.
[4] S. K. Shivakumar, “Digital workplace development,” in Apress eBooks, pp. 77–108, 2019, doi: 10.1007/978-1-4842-5512-4_4.
[5] A. Loukiala, J. Joutsenlahti, M. Raatikainen, T. Mikkonen, and T. Lehtonen, “Migrating from a centralized data warehouse to a decentralized data platform architecture,” Lecture Notes in Computer Science, pp. 36–48, 2021, doi: 10.1007/978-3-030-91452-3_3.
[6] C. Tselios and G. Tsolis, “A survey on software tools and architectures for deploying multimedia-aware cloud applications,” Lecture Notes in Computer Science, pp. 168–180, 2016, doi: 10.1007/978-3-319-29919-8_13.
[7] S. K. Shivakumar, “Modern web platform performance principles,” in Apress eBooks, pp. 105–143, 2020, doi: 10.1007/978-1-4842-6528-4_5.
[8] P. Raj and A. Raman, “The distinct trends and transitions in the information technology (IT) space,” in Computer Communications and Networks, pp. 1–12, 2018, doi: 10.1007/978-3-319-78637-7_1.
[9] A. Portier, H. Carter, and C. Lever, “Security in plain TXT,” Lecture Notes in Computer Science, pp. 374–395, 2019, doi: 10.1007/978-3-030-22038-9_18.
[10] İ. Met, D. Kabukçu, G. Uzunoğulları, Ü. Soyalp, and T. Dakdevir, “Transformation of business model in finance sector with artificial intelligence and robotic process automation,” in Contributions to Management Science, pp. 3–29, 2019, doi: 10.1007/978-3-030-29739-8_1.
[11] E. Bertin, N. Crespi, and T. Magedanz, “Evolution of telecommunication services,” Lecture Notes in Computer Science, 2013, doi: 10.1007/978-3-642-41569-2.
[12] B. Nicoletti, “Partnerships in Banking 5.0,” in Palgrave Studies in Financial Services Technology, pp. 359–368, 2021, doi: 10.1007/978-3-030-75871-4_11.
[13] M. T. Jakóbczyk, “Cloud-native architecture,” in Apress eBooks, pp. 487–551, 2020, doi: 10.1007/978-1-4842-5506-3_9.
[14] S. Furnell, P. Fischer, and A. Finch, “Can’t get the staff? The growing need for cyber-security skills,” Computer Fraud & Security, vol. 2017, no. 2, pp. 5–10, 2017, doi: 10.1016/S1361-3723(17)30013-1.
[15] J. H. Cheung, D. K. Burns, R. R. Sinclair, and M. Sliter, “Amazon Mechanical Turk in organizational psychology: An evaluation and practical recommendations,” Journal of Business and Psychology, vol. 32, no. 4, pp. 347–361, 2016, doi: 10.1007/s10869-016-9458-5.
[16] M. P. Robillard and R. DeLine, “A field study of API learning obstacles,” Empirical Software Engineering, vol. 16, no. 6, pp. 703–732, 2010, doi: 10.1007/s10664-010-9150-8.
[17] C. Cheng, H. Yao, and T. Wu, “Applying data mining techniques to analyze the causes of major occupational accidents in the petrochemical industry,” Journal of Loss Prevention in the Process Industries, vol. 26, no. 6, pp. 1269–1278, 2013, doi: 10.1016/j.jlp.2013.07.002.
[18] T. Dagget, A. Molla, and T. Belachew, “Job related stress among nurses working in Jimma Zone public hospitals, South West Ethiopia: A cross sectional study,” BMC Nursing, vol. 15, no. 1, Art. no. 39, 2016, doi: 10.1186/s12912-016-0158-2.
[19] M. Sarstedt and E. Mooi, “Descriptive statistics,” in Springer Texts in Business and Economics, pp. 91–150, 2018, doi: 10.1007/978-3-662-56707-4_5.
[20] D. Yang and M. Li, “Evolutionary approaches and the construction of technology-driven regulations,” Emerging Markets Finance and Trade, vol. 54, no. 14, pp. 3256–3271, 2018, doi: 10.1080/1540496X.2018.1496422.
[21] A. Jacobsson, M. Boldt, and B. Carlsson, “A risk analysis of a smart home automation system,” Future Generation Computer Systems, vol. 56, pp. 719–733, 2015, doi: 10.1016/j.future.2015.09.003.
[22] K. D. Mandl et al., “The Genomics Research and Innovation Network: Creating an interoperable, federated, genomics learning system,” Genetics in Medicine, vol. 22, no. 2, pp. 371–380, 2019, doi: 10.1038/s41436-019-0646-3.
[23] S. Preibisch, “Real-life API examples,” in Apress eBooks, pp. 159–169, 2018, doi: 10.1007/978-1-4842-4140-0_9.
[24] E. Varga, “Modular design,” in Apress eBooks, pp. 17–43, 2016, doi: 10.1007/978-1-4842-2196-9_2.
[25] V. Pizurica and P. Vandaele, “A cloud-based Bayesian smart agent architecture for Internet-of-Things applications,” Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, pp. 42–47, 2015, doi: 10.1007/978-3-319-19656-5_6.
[26] P. Daugherty and J. Euchner, “Human + machine: Collaboration in the age of AI,” Research-Technology Management, vol. 63, no. 2, pp. 12–17, 2020, doi: 10.1080/08956308.2020.1707001.
[27] L. O. Colombo-Mendoza, R. Valencia-García, R. Colomo-Palacios, and G. Alor-Hernández, “A knowledge-based multi-criteria collaborative filtering approach for discovering services in mobile cloud computing platforms,” Journal of Intelligent Information Systems, vol. 54, no. 1, pp. 179–203, 2018, doi: 10.1007/s10844-018-0527-2.
[28] S. Varghese, “Authentication to web apps,” in Apress eBooks, pp. 121–140, 2015, doi: 10.1007/978-1-4842-1052-9_7.
[29] S. Ganguly, “QML: Way forward,” in Apress eBooks, pp. 461–496, 2021, doi: 10.1007/978-1-4842-7098-1_9.
Copyright (c) 2024 Afsara Tasnim Shama

This work is licensed under a Creative Commons Attribution 4.0 International License.
