Expert Advice Community

Guest

3rd party security policy vs. Information security policy for supplier relations

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

3rd party security policy vs. Information security policy for supplier relations

According to ISO 27K requirement (Information security policy for supplier relationship) may i know what is different between 3rd party security policy and  Information security policy for supplier relationships?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

Answer: ISO 27001 does not mention "3rd party security policy", so the point is:

1) ISO 27001 requires you to make only one policy to deal with suppliers

2) The difference between 3rd parties and suppliers is that 3rd parties could also include customers

3) Even if you want to cover the security requirements for customers and suppliers, you can do it in one policy, you do not have to separate them.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics