Policy Register

Suppliers and third parties

What the organisation asks of the parties it depends on: the policy, the assessment, the contract terms, the cloud provider, the outsourcer.

Policy types in this family

7

What reaches this family

ISO 27001Expects: supplier and third-party security policy. Requires, by clause: ISO 27001 5.23, ISO 27001 8.30, ISO 27001 5.22, ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.21.
ISO 27701Expects: no document of this family on its gap list. Requires, by clause: ISO 27701 A.3.10.
ISO 42001Expects: supplier and third-party security policy. Requires, by clause: ISO 42001 A.10.3.
DORAExpects: supplier and third-party security policy. Requires, by clause: DORA Art. 28, DORA Art. 30.
NIS2Expects: supplier and third-party security policy. Requires, by clause: NIS2 Art. 21(2)(d), NIS2 Art. 21(3).

Register the documents in this family

Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.

Build a register