Supplier Relationship Policy¶
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Jan/2024 | Initial Copy | [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Objectives¶
The objective of this policy is to protect tecciance’s assets that are accessed by suppliers, by identifying the risks associated with the supplier’s access to tecciance /client premises and/or information and information processing facilities.
Scope¶
This policy shall apply to all vendors providing services to tecciance. The services rendered shall include any or all the following:
-
Requiring access to tecciance / tecciance’s client information assets
-
Hosting tecciance / tecciance’s client information assets
Requirement¶
Information Security in Supplier Relationships¶
Information Security Policy for Supplier Relationships¶
-
Evaluate and document information security risks before deciding the engagement of suppliers based on category of suppliers.
-
Information security requirements to be complied shall be communicated to suppliers as part of the contractual agreement.
-
Suppliers shall be briefed on their information security roles and responsibilities prior to being granted access to any tecciance information assets / systems / facilities in line with requirements specified in the contract.
-
tecciance shall periodically update suppliers regarding applicable and acceptable security practices.
-
Maintain a consolidated list of Supplier inventory and reassess suppliers periodically where risk was accepted during onboarding and to cross check if the risk has been mitigated or needs to be addressed/accepted.
Addressing Security within Supplier Agreements¶
Information security requirements are addressed as part of the supplier agreement, and necessary controls are implemented based on the risk category of the supplier. It will be ensured that the agreements with third parties involving accessing, processing, communicating, or managing the organizational information or processing facilities or adding products or services to the information processing facilities shall adhere to the information security requirements of tecciance.
Information and Communication Technology Supply Chain¶
-
Agreement with critical technology service providers shall cover secure transfer and availability of the network.
-
tecciance shall communicate any specific security and availability requirements to the supplier as part of the contract.
-
tecciance shall ensure that sensitive information received in any form from its clients shall be protected during transmission.
Supplier Service Delivery Management¶
Monitoring and Review of Supplier Services
The respective functions shall monitor and review the records and reports provided by suppliers to ensure that the information security terms and conditions of the agreements are being adhered to.
-
Service performance levels to check adherence to the agreements.
-
Service reports produced by the supplier.
-
For high-risk vendors, perform audits and review compliance to agreed terms.
-
Supplier’s capability to maintain service continuity.
Managing Changes to Supplier Services¶
The respective functions and other relevant stakeholders shall manage the changes to the provision of services, considering the criticality of business systems, processes involved and the reassessment of risks.
Review¶
This Policy and Procedure shall be reviewed and approved by IS Head once a year or at the time of any major change in existing environment affecting policy, whichever is earlier.
Exceptions¶
Any exceptions to this Policy and Procedure shall be reviewed and approved by IS Head before acceptance.
Control Mapping¶
Mapping to ISO 27001 control (s)¶
| ISO 27001:2022 Control | Control Objective |
|---|---|
| A.5.19 | Information security in supplier relationships |
| A.5.20 | Addressing information security within supplier agreements |
| A.5.21 | Managing information security in the information and communication technology (ICT) supply chain |
| A.5.22 | Monitoring, review and change management of supplier services |
¶
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.
AI, cloud-model, and coding-assistant suppliers are ICT suppliers. Contracts shall address training-data use, subprocessors, incident notice, and audit or equivalent assurance.