This template establishes a repeatable process for assessing the security risk a new vendor introduces before, and after, they’re onboarded.
1. Purpose
This policy establishes a consistent process for assessing and monitoring the security risk introduced by third-party vendors with access to [Organization Name] systems or data.
2. Vendor Risk Tiers
- High Risk: Vendors with access to Restricted data or critical systems
- Medium Risk: Vendors with access to Confidential data or limited system access
- Low Risk: Vendors with no access to sensitive data or systems
3. Pre-Onboarding Due Diligence
Before contracting with a High or Medium Risk vendor, [Security/Procurement] will require evidence of the vendor’s security posture, such as a SOC 2 report, security questionnaire responses, or equivalent documentation.
4. Contractual Requirements
Contracts with High and Medium Risk vendors must include data protection terms, breach notification obligations within [timeframe], and the right to audit where appropriate.
5. Ongoing Monitoring
High Risk vendors are reassessed at minimum [annually]; Medium Risk vendors at minimum [every two years]. Any material change in a vendor’s service or a public security incident affecting the vendor triggers an off-cycle review.
6. Vendor Inventory
[Owner/team] maintains a current inventory of all active vendors, their risk tier, and their data access scope.
7. Offboarding
Upon contract termination, vendor access to systems and data is revoked within [timeframe], and the vendor must confirm secure deletion or return of any organizational data in their possession.
Want this built and implemented for your organization?
A template is a starting point. Cyberix builds, customizes, and maintains policies like this as part of a full GRC engagement.
