What to Provide
Vendor Risk Management Policy
The evidence should demonstrate:
Vendor risk assessment process
Vendor risk rating process
Critical vendor management process
Requirement for critical vendors to be reviewed annually
Security requirements for vendors
Date of last review and document version numbering
Evidence Format
Exported word processing document in a common file type such as .docx or .pdf.
Associated Unified Control ID | Associated Framework Control |
CTRL-1094 | LCL-27 |