markdowneditor

Supplier & Third-Party Security Assessment

Vendor vetting + ongoing monitoring

사용법: Run before onboarding, not after. Certifications (SOC2/ISO 27001) shortcut the checklist but never skip the exit/data-deletion terms.

미리보기

Supplier & Third-Party Security Assessment

ISO/IEC 27001:2022 A.5.19-A.5.23 (supplier relationships, supply chain, cloud services). Assess BEFORE onboarding + periodically.

FieldValue
Vendorcompany name
Assessment dateYYYY-MM-DD
Assessed by@name
Servicewhat they provide
Data accessedclassification of data they touch
Risk levelCritical / High / Medium / Low

1. Vendor profile

  • Company, size, location, years in business
  • Service provided to us
  • Data they'll access (classification level)
  • Will they host data? Subprocess?

2. Security posture checklist

AreaAssessmentEvidenceOK?
CertificationsISO 27001, SOC 2, etc.cert refs
Access controltheir own MFA, least privilege
Data protectionencryption at rest/transit
Incident responseplan, notification SLA
Business continuitytheir BCP, SLA uptime
Subcontractingwho they subcontract tolist
Data locationwhere data is storedregions
Deletion/exitdata return + deletion on exit

3. Risk determination

FactorRatingNotes
Data sensitivityhigh/med/low
Criticality to operations
Vendor security maturity
Overall risk

4. Required controls

  • Contract: security clauses + breach notification SLA
  • Right to audit clause
  • Data processing agreement (if personal data)
  • Return/deletion on termination

5. Ongoing monitoring

  • Review frequency: annual (critical vendors) / bi-annual (others)
  • Monitoring: SOC reports reviewed, incidents tracked

6. Decision

  • Approved
  • Approved with conditions:
  • Rejected

Signed: ____________ Date: ________

관련 템플릿