Expert Advice Community

Guest

Gathering information from suppliers

  Quote
Guest
Guest user Created:   Apr 23, 2019 Last commented:   Apr 23, 2019

Gathering information from suppliers

In my organization, we are on the way to getting an critical application from a third party company and the company will share front end SDK, we need to manage after taking handover, they will not share source code and afterwards, they will be engaged only if code level change/patch or any bug need to be fixed. I asked the company to share their Information Security related policies like, System Acquisition, Development & Maintenance, Data Security & Privacy Protection, System Vulnerability & Risk Management, and some other policies. But they have denied to share their internal policies, what should I do in this case? I need your expert guidance.
0 0

Assign topic to the user

ISO 27001 SUPPLIER SECURITY POLICY

Define how suppliers and partners need to keep your information safe.

ISO 27001 SUPPLIER SECURITY POLICY

Define how suppliers and partners need to keep your information safe.

Expert
Rhand Leal Apr 23, 2019

What are the mandatory resources need to collect for review/risk assessment purposes from application supplier/vendor?

Answer:

In a general manner you have these options to consider:
- Propose to sign a Non Disclosure Agreement to have access to their policies
- Ask for a general view only of these policies to see if they can fulfill your needs
- Ask them about how they handle your specific risks related to this critical application

If none of these alternatives are possible, you should consider if the risk of taking over the application without these information is acceptable, or if you should consider another supplier for this application.

Regarding mandatory resources to collect, ISO 27001 is not prescriptive. The information you will need will depend on the results of risk assessment and legal requirements your organization has to fulfill.

Based on risk assessment and legal requirements you can sign a service agreement with this supplier including security clauses that specify if the access to documentation is needed or not.

These article will provide you further explanation about managing suppliers:
- 6-step process for handling supplier security according to ISO 27001https://advisera.com/27001academy/blog/2014/06/30/6-step-process-for-handling-supplier-security-according-to-iso-27001/
- Which security clauses to use for supplier agreements? https://advisera.com/27001academy/blog/2017/06/19/which-security-clauses-to-use-for-supplier-agreements/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 23, 2019

Apr 23, 2019

Suggested Topics