Assess a vendor you already use
Use a cloud service's public trust or security page to fill in a short vendor questionnaire, and decide which agreements you'd need with them.
Environment
A browser and a spreadsheet. Pick a SaaS product you use.
Before you start
- Read Vendor Selection (p.404), Vendor Assessment Methods (p.406) and Legal Agreements (p.408).
You will
- Gather vendor assurance evidence
- Rate vendor risk
- Match needs to agreement types
Steps
-
1
Find the vendor's trust, security or compliance page.
-
2
Record: certifications or audit reports offered (e.g. ISO 27001, SOC 2), data locations, encryption at rest and in transit, MFA and SSO support, breach notification commitments, and their subprocessor list.
-
3
Note what's missing or only available under NDA.
-
4
Rate the vendor low, medium or high risk for your use, and explain why.
-
5
List the agreements you'd want before trusting them with company data (NDA, SLA, MSA, data processing terms) and what each covers.
-
6
Write how you'd monitor the vendor after onboarding.
Check your understanding
- ?What does an independent audit report give you that the vendor's own claims don't?
- ?What belongs in an SLA?
- ?Why does the vendor's subprocessor list matter for supply chain risk?