Vendor Management Policy
Provide your Vendor Risk Management Policy
The evidence should demonstrate:
Vendor risk assessment process
Vendor risk rating process
Critical vendor management process
Requirement for critical vendors to be reviewed annually
Security requirements for vendors
Date of last review and document version numbering
Associated Unified Control ID | Associated Framework Control |
CTRL-1094 | LCL-27 |