Expert Advice Community

Guest

Vendor Management Policy

  Quote
Guest
Guest user Created:   Jan 25, 2018 Last commented:   Jan 25, 2018

Vendor Management Policy

I can't seem to find a Vendor Management Policy in the ISO 27001 Documentation Toolkit. Am I just missing it? Or, is there simply no such policy in the Toolkit?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 25, 2018

Answer: Regarding suppliers, ISO 27001 has a control that requires the definition of requirements for mitigating the risks associated with a supplier’s access to the organization’s assets, which does not require to describe detailed practices. This control is covered by template "Supplier Security Policy" that can be found at folder 08 Annex A A.15 Supplier relationships.

If you need detailed rules about how a supplier should behave, you can use the "Security Clauses for Suppliers and Partners" template, located at folder 08 Annex A A.15 Supplier relationships to define the rules you want your vendors to follow.

This article will provide you further explanation about suppliers management:
- Which security clauses to use for supplier agreements? https://advisera.com/27001academy/blog/2017/06/19/which-security-clauses-to-use-for-supplier-agreements/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 24, 2018

Jan 24, 2018