Suppliers and third parties
What the organisation asks of the parties it depends on: the policy, the assessment, the contract terms, the cloud provider, the outsourcer.
Policy types in this family
7- Cloud vendor management policy policy
How cloud providers in particular are chosen, contracted, monitored and left, with the exit plan and the data return written down. Required by ISO 27001, DORA; owner procurement or the vendor manager, with the information security lead. - Outsourcing policy policy
The conditions for handing a function or a development to an external party: the approval, the oversight, the access and the return. Required by ISO 27001, DORA; owner procurement or the vendor manager, with the information security lead. - Service level management policy policy
How supplier service levels are set, measured, reviewed and acted on, and how changes to a service are handled. Required by ISO 27001; owner procurement or the vendor manager, with the information security lead. - Supplier and third-party security policy policy
How suppliers are selected, what security terms they are held to, how they are monitored and reviewed, and how the relationship ends. Required by ISO 27001, ISO 27701, ISO 42001, DORA, NIS2; owner procurement or the vendor manager, with the information security lead. - Supply chain security policy policy
How risk beyond the direct supplier is handled: components, sub-processors, provenance, the tiers below the contract. Required by ISO 27001, NIS2; owner procurement or the vendor manager, with the information security lead. - Vendor contract security requirements standard
The standard security terms written into every supplier agreement: access, incident notice, audit rights, sub-contracting, exit. Required by ISO 27001, DORA, NIS2; owner procurement or the vendor manager, with the information security lead. - Vendor security assessment procedure procedure
How a supplier is assessed before contract and on a cycle after it: the questionnaire, the evidence asked for, the scoring and who signs it off. Required by ISO 27001, DORA; owner procurement or the vendor manager, with the information security lead.
What reaches this family
| ISO 27001 | Expects: supplier and third-party security policy. Requires, by clause: ISO 27001 5.23, ISO 27001 8.30, ISO 27001 5.22, ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.21. |
|---|---|
| ISO 27701 | Expects: no document of this family on its gap list. Requires, by clause: ISO 27701 A.3.10. |
| ISO 42001 | Expects: supplier and third-party security policy. Requires, by clause: ISO 42001 A.10.3. |
| DORA | Expects: supplier and third-party security policy. Requires, by clause: DORA Art. 28, DORA Art. 30. |
| NIS2 | Expects: supplier and third-party security policy. Requires, by clause: NIS2 Art. 21(2)(d), NIS2 Art. 21(3). |
Register the documents in this family
Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.
Build a register