Supplier & Third-Party Security Assessment
Vendor vetting + ongoing monitoring
사용법: Run before onboarding, not after. Certifications (SOC2/ISO 27001) shortcut the checklist but never skip the exit/data-deletion terms.
미리보기
Supplier & Third-Party Security Assessment
ISO/IEC 27001:2022 A.5.19-A.5.23 (supplier relationships, supply chain, cloud services). Assess BEFORE onboarding + periodically.
| Field | Value |
|---|---|
| Vendor | company name |
| Assessment date | YYYY-MM-DD |
| Assessed by | @name |
| Service | what they provide |
| Data accessed | classification of data they touch |
| Risk level | Critical / High / Medium / Low |
1. Vendor profile
- Company, size, location, years in business
- Service provided to us
- Data they'll access (classification level)
- Will they host data? Subprocess?
2. Security posture checklist
| Area | Assessment | Evidence | OK? |
|---|---|---|---|
| Certifications | ISO 27001, SOC 2, etc. | cert refs | |
| Access control | their own MFA, least privilege | ||
| Data protection | encryption at rest/transit | ||
| Incident response | plan, notification SLA | ||
| Business continuity | their BCP, SLA uptime | ||
| Subcontracting | who they subcontract to | list | |
| Data location | where data is stored | regions | |
| Deletion/exit | data return + deletion on exit |
3. Risk determination
| Factor | Rating | Notes |
|---|---|---|
| Data sensitivity | high/med/low | |
| Criticality to operations | ||
| Vendor security maturity | ||
| Overall risk |
4. Required controls
- Contract: security clauses + breach notification SLA
- Right to audit clause
- Data processing agreement (if personal data)
- Return/deletion on termination
5. Ongoing monitoring
- Review frequency: annual (critical vendors) / bi-annual (others)
- Monitoring: SOC reports reviewed, incidents tracked
6. Decision
- Approved
- Approved with conditions:
- Rejected
Signed: ____________ Date: ________