Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R13_Lieferanten-und-Dienstleistersteuerung.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

12 KiB

Policy Supplier and Service Provider Management

Document information Value
Document type Policy
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Responsible {{ROLE_ISB}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This policy governs ensuring information security at suppliers, confidentiality agreements and the delineation of responsibilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.

2. Scope

This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).

3. Requirements and implementation

Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).

3.1 Information security at suppliers

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 6.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.19, A.5.22{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] Contractors and partners are subjected to a security risk assessment.
  • [MUST] An appropriate level of information security is ensured through contractual agreements with contractors and partners.
  • [MUST] Where applicable, contractual agreements with clients/customers are passed on to contractors and partners. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Performance reports and documents from contractors and partners are reviewed. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
  • [VERY HIGH] The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
  • [VERY HIGH] Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A) {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.5.19] Processes to manage the information security risks arising from supplier relationships are defined and implemented.
  • [ISO A.5.22] The information security of supplier services is monitored and reviewed regularly, and changes are managed. {{/if}}

Implementation at {{ORG_NAME}}

Contractors/partners are subjected to a security risk assessment (BL-SUP-01) and contractually obliged to an appropriate level of information security (incl. passing on to subcontractors and customer requirements); the supplier register is maintained in the ISMS tool ({{TOOL_NAME}}), and performance reports are reviewed (see {{LINK:VA-10}}).

{{#if FLAG_ELEVATED_PROTECTION}}

Where the protection need is high, the supplier's level of security is demonstrated (self-disclosure/attestation/certificate/audit) and compliance is documented and monitored regularly and upon changes. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the evidence is provided via a third-party audit (TISAX or similar) or a documented risk-based management decision; transparency obligations regarding supply chain risks are fulfilled.{{/if}} {{/if}}

3.2 Confidentiality agreements

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 6.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.20{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] The confidentiality requirements are determined and met.
  • [MUST] Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.
  • [MUST] Valid confidentiality agreements are concluded before information requiring protection is passed on.
  • [MUST] The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Templates for confidentiality agreements are available and checked for legal applicability. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented. {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.5.20] Relevant information security requirements are agreed with each supplier and recorded contractually. {{/if}}

Implementation at {{ORG_NAME}}

Confidentiality requirements are determined and known; before information requiring protection is passed on, valid NDAs based on reviewed standard templates (process see {{LINK:VA-10}}) (with parties, type of information, subject matter, validity, responsibilities and post-contractual provisions) are concluded and stored in the ISMS tool. Requirements/procedures and periods of validity are monitored regularly, and ways to demonstrate compliance are defined.

3.3 Delineation of responsibilities

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 6.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.21{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] The IT services concerned are identified.
  • [MUST] The security requirements relevant to the IT service are determined.
  • [MUST] The organisation responsible for implementing the requirement is defined and aware of its responsibility.
  • [MUST] Mechanisms for shared responsibilities are specified and implemented.
  • [MUST] The responsible organisation fulfils its respective responsibilities. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] The responsible personnel is appropriately trained. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] The applicability of the ISA controls has been assessed and documented. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] The service configuration is included in the regular security assessments. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A) {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.5.21] Processes to manage information security risks in the ICT product and service supply chain are defined and implemented. {{/if}}

Implementation at {{ORG_NAME}}

The IT services concerned and their security requirements are identified; responsibilities between the organisation and external IT service providers (incl. mechanisms for shared responsibility) are defined, known and fulfilled (see {{LINK:VA-10}}); the IT services and service providers concerned are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}). The configuration is implemented on a requirements basis and documented, and the personnel is trained.

{{#if FLAG_ELEVATED_PROTECTION}}

Where the protection need is high, a list of the IT services and responsible service providers exists, the applicability of the ISA controls is assessed/documented, the service configuration is part of regular security assessments, the fulfilment of responsibility is demonstrated, and the integration into local protective measures is documented. {{/if}}

4. Binding nature

This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.

5. Roles and responsibilities

Role Responsibility in this policy
{{ROLE_ISB}} Supplier management
Procurement Contractual integration

6. Review and update

This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.

7. Evidence

The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).

  • Associated procedures: {{LINK:VA-10}}
  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}
  • Evidence register: {{LINK:NACHWEISREGISTER}}
  • Further: {{LINK:R01}}, {{LINK:R12}}