You may be a business who as a data controller is required to carry out security due diligence assessment of any data processor. Alternatively, you may be a business whose customers or insurers contractually require you to carry out third-party security assessments of all your suppliers. In either case it is a challenge to decide how to carry-out a security assessment which is effective, not too onerous on your business or your supplier and offers value for money.
There are on-line third-party supplier risk assessment tools, but they often have a large question set and require tailoring to meet your needs. But what about if your supplier is a large organisation such as SalesForce or Oracle HR, they are not going to complete a security questionnaire.
These on-line solutions can be expensive so you could create your own but what questions do you need to ask and how are you going to assess the responses?
We have helped medium to large companies assess the security of their suppliers. We have produced pragmatic security questionnaires tailored to the business, the supplier and the level of risk. We then helped the supplier to complete the questionnaire, evaluated the responses and advised on the risk and any security clauses that need to be added in the contract with the supplier.
Where the customer had a large supplier, we took the information from the supplier’s published security document and completed a due-diligence report that satisfied the contractual and legal obligations.
Where required we can carry-out onsite audits of suppliers.