SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Vendor Reviews

  Quote
Guest
Guest user Created:   Nov 06, 2020 Last commented:   Nov 06, 2020

Vendor Reviews

I work for ***, which provides software and services to help companies do webinars. I'm trying to figure out if certain companies that we use their services need to be on our Vendor Log, and if we need to perform periodic vendor reviews for them, etc. It is clear to me that our Key Vendors and all vendors who interface with our software would need to be included. But what about companies like ***, who helps us manage our social accounts? It is not clear to me where the line is in cases like this.
Thanks very much.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 06, 2020

I'm assuming that by "Vendor log" you mean the document or system you use to record and manage your vendors.

Considering that, to identify which vendors should be in your Vendor Log, and under periodic vendor review, you need to perform a risk assessment on your vendors, to identify if they can rise relevant risks that need treatment. Additionally, you need to evaluate the legal requirements you must comply with (e.g., laws, regulations and contracts), to identify if any of them has clauses defining specific vendors or conditions that will require vendors to be logged or reviewed periodically.

These articles can provide further information:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 06, 2020

Nov 06, 2020