# Policy Supplier and Service Provider Management | Document information | Value | |-----------------------|------| | Document type | Policy | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Responsible | {{ROLE_ISB}} | | Approved by | {{ROLE_MANAGEMENT}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This policy governs ensuring information security at suppliers, confidentiality agreements and the delineation of responsibilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027. ## 2. Scope This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Requirements and implementation > Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary). ### 3.1 Information security at suppliers *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.19, A.5.22{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** Contractors and partners are subjected to a security risk assessment. - **[MUST]** An appropriate level of information security is ensured through contractual agreements with contractors and partners. - **[MUST]** Where applicable, contractual agreements with clients/customers are passed on to contractors and partners. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Performance reports and documents from contractors and partners are reviewed. {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}} - **[VERY HIGH]** The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}} - **[VERY HIGH]** Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A) {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.5.19]** Processes to manage the information security risks arising from supplier relationships are defined and implemented. - **[ISO A.5.22]** The information security of supplier services is monitored and reviewed regularly, and changes are managed. {{/if}} **Implementation at {{ORG_NAME}}** Contractors/partners are subjected to a security risk assessment (BL-SUP-01) and contractually obliged to an appropriate level of information security (incl. passing on to subcontractors and customer requirements); the supplier register is maintained in the ISMS tool ({{TOOL_NAME}}), and performance reports are reviewed (see {{LINK:VA-10}}). {{#if FLAG_ELEVATED_PROTECTION}} Where the protection need is high, the supplier's level of security is demonstrated (self-disclosure/attestation/certificate/audit) and compliance is documented and monitored regularly and upon changes. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the evidence is provided via a third-party audit (TISAX or similar) or a documented risk-based management decision; transparency obligations regarding supply chain risks are fulfilled.{{/if}} {{/if}} ### 3.2 Confidentiality agreements *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.20{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** The confidentiality requirements are determined and met. - **[MUST]** Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection. - **[MUST]** Valid confidentiality agreements are concluded before information requiring protection is passed on. - **[MUST]** The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Templates for confidentiality agreements are available and checked for legal applicability. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented. {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.5.20]** Relevant information security requirements are agreed with each supplier and recorded contractually. {{/if}} **Implementation at {{ORG_NAME}}** Confidentiality requirements are determined and known; before information requiring protection is passed on, valid NDAs based on reviewed standard templates (process see {{LINK:VA-10}}) (with parties, type of information, subject matter, validity, responsibilities and post-contractual provisions) are concluded and stored in the ISMS tool. Requirements/procedures and periods of validity are monitored regularly, and ways to demonstrate compliance are defined. ### 3.3 Delineation of responsibilities *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.21{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** The IT services concerned are identified. - **[MUST]** The security requirements relevant to the IT service are determined. - **[MUST]** The organisation responsible for implementing the requirement is defined and aware of its responsibility. - **[MUST]** Mechanisms for shared responsibilities are specified and implemented. - **[MUST]** The responsible organisation fulfils its respective responsibilities. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The responsible personnel is appropriately trained. {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** The applicability of the ISA controls has been assessed and documented. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** The service configuration is included in the regular security assessments. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A) {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.5.21]** Processes to manage information security risks in the ICT product and service supply chain are defined and implemented. {{/if}} **Implementation at {{ORG_NAME}}** The IT services concerned and their security requirements are identified; responsibilities between the organisation and external IT service providers (incl. mechanisms for shared responsibility) are defined, known and fulfilled (see {{LINK:VA-10}}); the IT services and service providers concerned are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}). The configuration is implemented on a requirements basis and documented, and the personnel is trained. {{#if FLAG_ELEVATED_PROTECTION}} Where the protection need is high, a list of the IT services and responsible service providers exists, the applicability of the ISA controls is assessed/documented, the service configuration is part of regular security assessments, the fulfilment of responsibility is demonstrated, and the integration into local protective measures is documented. {{/if}} ## 4. Binding nature This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}. ## 5. Roles and responsibilities | Role | Responsibility in this policy | |-------|-------------------------------------| | {{ROLE_ISB}} | Supplier management | | Procurement | Contractual integration | ## 6. Review and update This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}. ## 7. Evidence The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}). ## 8. Related documents - Associated procedures: {{LINK:VA-10}} - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}} - Evidence register: {{LINK:NACHWEISREGISTER}} - Further: {{LINK:R01}}, {{LINK:R12}}