Cyberstudy
Supplementary — not from your PDF Beginner ~35 min

Assess a vendor you already use

Use a cloud service's public trust or security page to fill in a short vendor questionnaire, and decide which agreements you'd need with them.

Environment

A browser and a spreadsheet. Pick a SaaS product you use.

Before you start

  • Read Vendor Selection (p.404), Vendor Assessment Methods (p.406) and Legal Agreements (p.408).

You will

  • Gather vendor assurance evidence
  • Rate vendor risk
  • Match needs to agreement types

Steps

  1. 1

    Find the vendor's trust, security or compliance page.

  2. 2

    Record: certifications or audit reports offered (e.g. ISO 27001, SOC 2), data locations, encryption at rest and in transit, MFA and SSO support, breach notification commitments, and their subprocessor list.

  3. 3

    Note what's missing or only available under NDA.

  4. 4

    Rate the vendor low, medium or high risk for your use, and explain why.

  5. 5

    List the agreements you'd want before trusting them with company data (NDA, SLA, MSA, data processing terms) and what each covers.

  6. 6

    Write how you'd monitor the vendor after onboarding.

Check your understanding

  • ?What does an independent audit report give you that the vendor's own claims don't?
  • ?What belongs in an SLA?
  • ?Why does the vendor's subprocessor list matter for supply chain risk?