Vendor Assessment Process
- Vendor Selection: Evaluate security posture, certifications (SOC 2, ISO 27001), financial stability, and references
- Due Diligence: Security questionnaires (SIG, CAIQ), penetration test results, policy reviews
- Contract Negotiation: Include security requirements, SLAs, right-to-audit clauses
- Ongoing Monitoring: Periodic reassessments, continuous threat intelligence monitoring for vendor breaches
- Offboarding: Ensure all data returned/destroyed; revoke all access; review data retention
Legal Agreements
| Agreement | Purpose |
|---|---|
| NDA (Non-Disclosure Agreement) | Protects confidential information shared with the vendor |
| SLA (Service Level Agreement) | Defines performance standards and remedies for failure (uptime %, response time, support tiers) |
| MSA (Master Service Agreement) | Overarching contract governing the relationship; references specific work orders/SOWs |
| SOW (Statement of Work) | Specific deliverables, timeline, and pricing for a project or service |
| MOU (Memorandum of Understanding) | Non-binding agreement outlining intent to work together; often used between government agencies |
| MOA (Memorandum of Agreement) | More formal than MOU; legally binding in some jurisdictions |
| ISA (Interconnection Security Agreement) | Documents technical and security requirements for a network interconnection between organizations |
| BPA (Business Partnership Agreement) | Defines relationship between business partners including data handling responsibilities |
Right to Audit
A contractual clause giving the customer the right to audit the vendor's security controls and practices. Essential for:
- Verifying vendor's security claims
- Regulatory compliance (demonstrating due diligence to regulators)
- Assurance that contractual security requirements are being met
Vendor Assessment Methods
- Penetration test results: Review vendor's most recent pen test report
- Vulnerability scan reports: Evidence of ongoing vulnerability management
- SOC 2 Type II report: Audited evidence that controls were effective over a 6–12 month period (not just designed)
- Certifications: ISO 27001, CSA STAR, FedRAMP, PCI DSS QSA audit
- Security questionnaire: CAIQ (Consensus Assessment Initiative Questionnaire) for cloud vendors
Supply Chain Risk Controls
- Mandate SBOM delivery for software vendors
- Code signing verification for software updates
- Hardware attestation / trusted supply chain programs (US government CMMC)
- Vendor diversification — don't rely on single vendors for critical components
- Monitor vendor breach news — subscribe to threat intel feeds that track vendor security incidents
Exam Tip: SLA = performance commitments. NDA = confidentiality. Right-to-audit = verify vendor security. SOC 2 Type II (audited over time) is more valuable than Type I (point-in-time). MSA is the umbrella; SOW is the specific project. ISA is specifically about network interconnections.