A compromise in either one of these applications can have a devastating impact on an institution and it’s relatively easy to envision this impact. A compromise can be due to a breach in integrity (e.g., why does everyone at the institution know that a celebrity has an account with the institution and has received a significant’sign-on’ bonus to work on a entertainment project); or confidentiality. The following items stand out to be a good starting point for any institution to follow for third-party applications: Does the vendor have an industry-recognized third party who conducts application vulnerability assessments on the application (including security)? If so, obtain the third party’s name and determine how often the assessment is conducted.”]
Source: https://www.cuinfosecurity.com/blogs/assessing-application-security-risk-assessment-p-28