# Supplier & Third-Party Security Assessment

> ISO/IEC 27001:2022 A.5.19-A.5.23 (supplier relationships, supply
> chain, cloud services). Assess BEFORE onboarding + periodically.

| Field | Value |
|-------|-------|
| Vendor | company name |
| Assessment date | YYYY-MM-DD |
| Assessed by | @name |
| Service | what they provide |
| Data accessed | classification of data they touch |
| Risk level | Critical / High / Medium / Low |

## 1. Vendor profile

- Company, size, location, years in business
- Service provided to us
- Data they'll access (classification level)
- Will they host data? Subprocess?

## 2. Security posture checklist

| Area | Assessment | Evidence | OK? |
|------|------------|----------|-----|
| Certifications | ISO 27001, SOC 2, etc. | cert refs | |
| Access control | their own MFA, least privilege | | |
| Data protection | encryption at rest/transit | | |
| Incident response | plan, notification SLA | | |
| Business continuity | their BCP, SLA uptime | | |
| Subcontracting | who they subcontract to | list | |
| Data location | where data is stored | regions | |
| Deletion/exit | data return + deletion on exit | | |

## 3. Risk determination

| Factor | Rating | Notes |
|--------|--------|-------|
| Data sensitivity | high/med/low | |
| Criticality to operations | | |
| Vendor security maturity | | |
| **Overall risk** | | |

## 4. Required controls

- [ ] Contract: security clauses + breach notification SLA
- [ ] Right to audit clause
- [ ] Data processing agreement (if personal data)
- [ ] Return/deletion on termination

## 5. Ongoing monitoring

- Review frequency: annual (critical vendors) / bi-annual (others)
- Monitoring: SOC reports reviewed, incidents tracked

## 6. Decision

- [ ] Approved
- [ ] Approved with conditions:
- [ ] Rejected

Signed: ____________ Date: ________
