ISO 27001 · the supplier security policy
The supplier security policy, written from a few answers
The company's data lives with its suppliers as much as on its own laptops, so the auditor asks for the list of them, the check before signing, the clause about breaches and the review, and this page writes those rules from a few answers: the critical suppliers, how they are assessed, which certificate counts, the notification window, where data may live, and how often the list is looked at.
The policy
Nine sections in the order a supplier is chosen, contracted, watched and left; an empty entry is written as a gap to fill, not skipped.
# Supplier security policy: [company] Policy owner: [the policy owner] · Approved by: [top management] Written on with the free page on getstandardos.com against the Annex A controls of ISO/IEC 27001:2022 on supplier relationships, security in supplier agreements, the ICT supply chain, the monitoring and review of supplier services and the use of cloud services. The wording is StandardOS's own. ## 1. Purpose and scope This policy sets the rules by which [company] chooses a supplier that will hold its information or run part of its service, what the contract with that supplier has to say, how the supplier is watched while the relationship lasts, and what happens when it ends. It applies to every supplier, cloud service, contractor and reseller that processes, stores or can reach the company's information, and to every person at the company who signs one up. ## 2. The supplier register and the tiers The company keeps a register of its suppliers with, for each: the service, the information it holds or reaches, the tier, the contract owner, the date of the last assessment and the date of the next review. A supplier is critical when it holds customer or personal data, runs part of the product, or could stop the company operating if it failed; every other supplier is standard. The critical suppliers at the date of this policy: [to be completed from the register]. ## 3. Before a supplier is signed A critical supplier is assessed before the contract is signed by reading its current certificate or audit report, checking that the scope covers the service the company will use, and recording the date and the result in the register. The company accepts a current ISO/IEC 27001 certificate or SOC 2 Type II report whose scope covers the service as evidence of the supplier's own security practice; a supplier without either answers the questionnaire in addition. A standard supplier is signed with the contract clauses in the next section and needs no assessment beyond a check that the service does not reach more information than the register says. ## 4. What every contract has to say A contract with a supplier that holds or reaches the company's information includes the following, in the supplier's terms or in the company's own agreement: - confidentiality of the company's information and its use only to deliver the service; - notification of a security incident affecting the company's information within 24 hours of the supplier becoming aware of it, with a named contact on each side; - no subcontracting of the service to another party that will reach the company's information without notice to the company and the same obligations passed on; - the right to receive the supplier's current certificate or audit report, and to ask questions about the service, at least once a year; - where the information is processed and stored, and a data processing agreement where personal data is involved; - the return or deletion of the company's information at the end of the contract, confirmed in writing, and the help needed to move to another supplier. ## 5. Cloud services The company's information is processed and stored in the EU or the EEA only. A cloud service that cannot offer that region for the information in question is not used for it. For every cloud service the register records what the provider secures and what the company has to secure itself, such as identities, access rights, configuration, backups and logging, and the owner of the company's side. ## 6. During the relationship Critical suppliers are reviewed once a year by [the policy owner]: the certificate or report is current, the incidents of the year are read, the service still matches the register, and the review is dated in the register. A review is also held when a supplier reports an incident, changes ownership, changes the region where information is processed, or is added to the product in a new way. A supplier that no longer meets this policy is given a date to fix it, or the exit section applies. ## 7. When a supplier is left When a contract ends, the contract owner obtains written confirmation that the company's information has been returned or deleted, removes the supplier's access to the company's systems, closes the accounts the company held with the supplier, and marks the supplier as ended in the register with the date. ## 8. Exceptions A supplier that cannot be signed on these terms may be used only with a written exception approved by [the policy owner], stating the rule not met, the information affected, the compensating measure and the date the exception is reviewed. ## 9. Records The register, the assessments, the contracts, the reviews, the exceptions and the exit confirmations are kept as the company's evidence that this policy is followed, and are what the internal audit and the certification audit read. Approved by [top management] on [date]; owned by [the policy owner]; reviewed at least once a year and whenever the company changes a critical supplier or a cloud service. This policy is written from the answers given. It is not certification advice; the certification body reads the policy for its rules and then samples the register, the contracts and the reviews against it, and the record it accepts is the one the company keeps.
In StandardOS the supplier register keeps itself
StandardOS holds the supplier register with each supplier's tier, certificate, contract date and review date, puts the reviews on the calendar at the cadence this policy sets, and shows the auditor the register beside the policy.
The DORA vendor questionnaireThe GDPR processor termsThe access control policyThe Annex A controls