2.4 KiB
2.4 KiB
Vendor & Third-Party Risk Management Guidance
Document owner: [Owner/Role]
Approved by: [Steering Committee / CISO]
Effective date: [YYYY-MM-DD]
Review cadence: [Annually]
1. Purpose & Scope
Implementation guidance for the Vendor & Third-Party Risk Management Policy. Applies to Procurement, Vendor Owners, and Security reviewing onboarding requests.
2. Tiering — Quick Decision Tree
- Does the vendor touch TLP:RED or TLP:AMBER+STRICT data, or sit on the kill-chain (per Authentication Policy §2.1)? → Critical.
- Does it touch TLP:AMBER data or run a significant business function? → High.
- Does it touch only TLP:GREEN data or have limited, non-privileged system access? → Medium.
- No system access, TLP:CLEAR only? → Low.
3. Due Diligence — Practical Checklist
- Request SOC 2 Type II (or ISO 27001 cert) — check the report period, not just that one exists; a report older than 12 months is effectively expired.
- For Critical vendors without a SOC 2 (common with smaller/newer vendors): require a completed security questionnaire (CAIQ or equivalent) plus a call with their security lead.
- Cyber insurance: confirm coverage amount is proportionate to potential exposure, not just that a certificate exists.
4. Concentration Risk — Worked Example
| Vendor | Function | Alternative Exists? | Exit Plan Status |
|---|---|---|---|
| Cloud IdP | Authentication for all staff | No (single IdP by design) | Required: documented break-glass + 90-day migration runbook — see Authentication Policy §2.11 |
| Payroll processor | Payroll | Yes (2 alternatives evaluated) | Lower priority — market has substitutes |
| Single MSP running all endpoint management | Device security | No | Required: document in-house fallback capability or dual-MSP readiness |
5. Offboarding Checklist
✅ Access revoked within 24h of termination.
✅ API keys/service accounts rotated or deleted.
✅ Data return or destruction certificate received and filed.
✅ Federated trust (SSO app registration, SAML/OIDC config) removed from IdP.
✅ Vendor Owner confirms no shared inbox/shared credential remains active.