Expert Advice Community

Guest

Access to suppliers SoA

  Quote
Guest
Guest user Created:   Oct 17, 2017 Last commented:   Oct 17, 2017

Access to suppliers SoA

I have a question regarding suppliers: Am I entitled to have access to a suppliers SoA?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Oct 17, 2017

Answer: For current suppliers you should consult the service agreement/contract established with each supplier. For new suppliers, to have an access to their SoA, should be condition of the suppliers selection process, because this document can provide you a general overview of how the supplier handles its own information security. But you should also note that suppliers can refuse to present their SoAs, and you should be prepared to consider that too in your selection process (maybe include visits to potential supplier's premises for evaluation).

These articles will provide you further explanation about management of suppliers' information security:
- 6-step process for handling supplier security according to ISO 27001 https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/
- Which security clauses to use for supplier agreements? https://advisera.com/27001academy/blog/2017/06/19/which-secur ity-clauses-to-use-for-supplier-agreements/

These materials will also help you regarding management of suppliers' information security:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 17, 2017

Oct 17, 2017

Suggested Topics

Guest user Created:   Oct 11, 2018 ISO 27001 & 22301
Replies: 1
0 0

Certified providers

Gerry Created:   Nov 27, 2023 ISO 27001 & 22301
Replies: 1
0 0

SoA Tasks