Vendor compliance checklist
Compliance, at its core, is a legal responsibility. It is defined as “act or process of doing what you have been asked or ordered to do.” Creating a successful vendor compliance program isn’t as simple as asking third parties to comply with your security requests or pestering them to answer your security risk assessment questions.
The vendor compliance checklist below highlights three things you must do if you want to ensure your vendors meet (or exceed) your security expectations.
1. All vendor security requests and obligations must be contractual.
Simply telling your vendor that you care about cybersecurity—or asking them to describe the controls they have in place to protect your data—is useless. If you want a strong vendor compliance program, including listing out all of your expectations in your vendor contract as part of your vendor compliance checklist.
This step cannot be skipped over. A data breach through a third party is bad enough—but discovering that your contractual agreement with the vendor who was breached didn’t clearly spell out security expectations is exponentially worse. The best time to define these contractual obligations is at the beginning of a vendor relationship, but you can—and should—revisit current vendor contracts to be sure they clarify your expectations.
Be specific when you create these legal documents. Telling your vendors they must implement “a reasonable amount of security measures” is meaningless. What is reasonable? Who defines it—you or your vendor? Specific and actionable language will protect you from legal scrutiny and liability.
2. Require your vendors to be aligned with frameworks and obtain certifications you feel strongly about.
You may choose for all your third parties to be compliant with ISO 27001, or align with the NIST risk management framework as part of your vendor compliance checklist. If so, you’ll need to write this plainly in your contract. Keep in mind that requirements like these will likely impact your vendors’ budgets, as many will need to hire a consultant to help build a security program that satisfies the controls.
3. Require your vendors to notify you when they experience a security incident.
Cybersecurity best practices dictate that you create a procedure for your third parties to notify you in the event of an incident that affects their organization and/or your data. Usually it’s a written procedure developed by an outside organization outlining who the third party is to contact if a security breach does occur. The first party is responsible for ensuring the vendor has the right procedures in place, so make sure your vendor compliance checklist includes accurate contact information, and a timeline of when that communication will happen for your vendors.