Compliance Framework Alignment
ISO/IEC 27001:2022 — Annex A.5.19 (Information security in supplier relationships) ISO/IEC 27001:2022 — Annex A.5.20 (Addressing information security within supplier agreements) ISO/IEC 27001:2022 — Annex A.5.21 (Managing information security in the ICT supply chain) ISO/IEC 27001:2022 — Annex A.5.22 (Monitoring, review and change management of supplier services) ISO/IEC 27001:2022 — Annex A.5.23 (Information security for use of cloud services) SOC 2 (AICPA TSC) — CC9.2 (Assesses and manages risks associated with vendors and business partners) PCI DSS v4.0.1 — Requirement 12.8 (Risk to information assets associated with TPSP relationships is managed) Digital Personal Data Protection Act, 2023 (DPDP Act, India) — data processor obligations This policy is aligned with ISO 27001:2022, SOC 2 & PCI DSS v4.0.1. ISO 27001 controls A.5.19-A.5.23 require documented supplier processes, security terms in agreements, ICT supply-chain assurance, ongoing monitoring, and cloud-service governance. SOC 2 CC9.2 requires assessment and management of vendor and business-partner risk. PCI DSS Requirement 12.8 (sub-requirements 12.8.1-12.8.5) requires a maintained TPSP list, written agreements, due diligence before engagement, monitoring of PCI DSS compliance status at least once every 12 months, and a responsibility matrix.
ACME TECHNOLOGIES PVT LTD SUPPLIER & THIRD-PARTY SECURITY POLICY Aligned with ISO 27001:2022, SOC 2 & PCI DSS v4.0.1
Effective Date [Effective Date]
Review Date [Review Date]
Framework Alignment ISO 27001:2022, SOC 2 & PCI DSS v4.0.1
Policy Owner / TPRM Lead Vikram Patel
Supplier Security Contact vendor-security@company.com Acme Technologies Pvt Ltd depends on suppliers, vendors, and third-party service providers to deliver its services. Each such relationship can extend the Company's attack surface and expose information assets to risk. This Policy establishes how Acme Technologies Pvt Ltd identifies, tiers, assesses, contracts with, monitors, and offboards suppliers so that information security is maintained across the entire supply chain and cloud estate.
1. Purpose and Scope
This Supplier & Third-Party Security Policy ("Policy") establishes the framework by which Acme Technologies Pvt Ltd manages information-security risk arising from suppliers, vendors, service providers, sub-processors, and third-party service providers (collectively, "Suppliers"). It applies to every Supplier that stores, processes, or transmits Company or customer information, connects to Company systems, or could otherwise affect the confidentiality, integrity, or availability of Company information assets, including any third-party service provider (TPSP) that could impact the security of the cardholder data environment (CDE). It supports compliance with ISO 27001:2022, SOC 2 & PCI DSS v4.0.1 (ISO 27001:2022 A.5.19).
2. Supplier Inventory and Ownership
Acme Technologies Pvt Ltd shall maintain a complete, current inventory of all Suppliers, recording for each: the services provided, the categories and classification of data accessed, connectivity to Company systems, the assigned business owner, the risk tier, and the current assurance status. The inventory shall explicitly flag every third-party service provider (TPSP) with which account data is shared or that could affect the security of the CDE, satisfying PCI DSS Requirement 12.8.1. A named business owner is accountable for each Supplier relationship throughout its lifecycle, and overall accountability for supervising Supplier risk rests with Vikram Patel (SOC 2 CC9.2).
3. Supplier Risk Tiering
Every Supplier shall be assigned a risk tier at engagement and re-assessed at each review, based on data sensitivity, system access, criticality to operations, and regulatory impact: (a) Tier 1 (Critical / High) — Suppliers processing Restricted or personal data, connected to production, or affecting the CDE; full assessment and annual review; (b) Tier 2 (Moderate) — Suppliers accessing Confidential data or non-production systems; assessment at onboarding and review at least every 24 months; (c) Tier 3 (Low) — Suppliers with no access to sensitive data or systems; lightweight intake screening. The risk tier determines the depth of due diligence, the contractual controls required, and the monitoring cadence.
4. Due Diligence Before Engagement
A documented due-diligence process shall be completed before any Supplier is engaged or any agreement is executed (PCI DSS Requirement 12.8.3; ISO 27001:2022 A.5.19). Due diligence shall include a security questionnaire, review of independent assurance evidence, a documented risk assessment, and — for Tier 1 Suppliers — review of financial stability, sub-processor chains, and jurisdiction / data-residency exposure. Due diligence for a proposed Supplier shall be completed within 30 days of request, and no Restricted or personal data may be shared, and no production access granted, until due diligence is approved by the business owner and Vikram Patel .
5. Security Requirements in Supplier Agreements
Written agreements shall be executed and maintained with every Supplier that accesses Company or customer information (ISO 27001:2022 A.5.20; PCI DSS Requirement 12.8.2). Agreements shall set out, as applicable to the risk tier: (a) information-classification handling and least-privilege access; (b) encryption of data at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher); (c) permitted use, retention limits, and prohibition on onward transfer without authorisation; (d) approval and flow-down of security obligations to sub-processors; (e) personnel screening, training, and confidentiality; (f) a breach-notification obligation requiring the Supplier to notify Acme Technologies Pvt Ltd within 24 hours of becoming aware of any security incident affecting Company data. Agreements with TPSPs shall include the TPSP's written acknowledgment that it is responsible for the security of account data it stores, processes, or transmits on behalf of the Company, or to the extent it could impact the security of the CDE (PCI DSS Requirement 12.8.2).
6. Data Processing Agreements (DPAs)
Where a Supplier processes personal data on behalf of Acme Technologies Pvt Ltd , a Data Processing Agreement (DPA) shall be executed in addition to the master agreement. The DPA shall define the subject-matter, nature, and purpose of processing; the categories of data subjects and personal data; the processor's obligations to process only on documented instructions; technical and organisational security measures; sub-processor authorisation and flow-down; assistance with data-subject rights and breach notification; and deletion or return of data on termination. DPAs shall reflect the obligations of a data processor under the Digital Personal Data Protection Act, 2023, and, for EU/UK personal data, incorporate the applicable UK GDPR / EU GDPR Article 28 terms and Standard Contractual Clauses for any restricted transfer.
7. Right to Audit and Assurance Evidence
Agreements with Tier 1 Suppliers shall grant Acme Technologies Pvt Ltd the right to audit the Supplier's information-security controls — directly or via an independent assessor — on at least 30 days' prior written notice, and immediately following a material security incident. In lieu of an on-site audit, the Company may accept current independent assurance evidence such as a SOC 2 Type II report or an ISO/IEC 27001 certificate with a Statement of Applicability. Such evidence shall be reviewed to confirm it is current, in-scope for the services consumed, and free of relevant qualifications or exceptions; identified gaps and complementary user-entity controls shall be tracked to closure.
8. ICT Supply-Chain Security
Information-security risk across the ICT supply chain shall be managed in accordance with ISO 27001:2022 A.5.21. For Suppliers of hardware, software, and ICT services this includes: (a) requiring suppliers to propagate security requirements throughout their own supply chain and to their sub-suppliers; (b) obtaining assurance over the components and code delivered, including software bill of materials (SBOM) where available; (c) requiring suppliers to notify the Company of security-relevant defects, vulnerabilities, and product recalls; (d) validating the authenticity and integrity of delivered hardware and software; and (e) assessing concentration and single-source dependency risk for critical ICT components.
9. Cloud Service Provider Governance
Information security for the use of cloud services shall be governed in accordance with ISO 27001:2022 A.5.23. Before adoption, each cloud service shall be assessed for data classification permitted, data residency, and the division of responsibilities under the shared-responsibility model. Agreements and configurations shall address: (a) allocation of security responsibilities between the Company and the provider; (b) identity, access, and key management retained by the Company where feasible; (c) logging, monitoring, and incident-notification commitments; (d) data portability and a defined exit / return process; and (e) provider assurance via SOC 2 Type II or ISO/IEC 27001 (and, where relevant, ISO/IEC 27017 / 27018). Provisioning of new cloud services outside this process ("shadow IT") is prohibited.
10. Ongoing Monitoring, Review and Change Management
Supplier service delivery and security posture shall be monitored, reviewed, and audited on a risk-based cadence (ISO 27001:2022 A.5.22). Tier 1 Suppliers shall be reviewed at least annually and Tier 2 at least every 24 months; reviews shall confirm continued adherence to agreed service levels and security obligations, and that SOC 2 / ISO 27001 attestations remain valid and in-scope. The Company shall operate a programme to monitor the PCI DSS compliance status of each TPSP at least once every 12 months, in line with PCI DSS Requirement 12.8.4. Material changes to a Supplier's services, sub-processors, ownership, locations, or security controls shall be assessed for risk before they take effect, and the Supplier's risk tier re-evaluated accordingly.
11. Responsibility Matrix and Shared Responsibilities
For each in-scope TPSP, Acme Technologies Pvt Ltd shall maintain a documented responsibility matrix recording which PCI DSS requirements are managed by the TPSP, which are managed by the Company, and which are shared between them (PCI DSS Requirement 12.8.5). More broadly, for every Supplier the Company shall document the allocation of security control responsibilities and any complementary user-entity controls it must implement to rely on the Supplier's assurance. The matrix shall be reviewed at each Supplier review and whenever the scope of services changes.
12. Incident Coordination and Issue Resolution
Suppliers shall report security incidents affecting Company or customer data to vendor-security@company.com within 24 hours of becoming aware of them, and shall cooperate fully with the Company's investigation, containment, and remediation. Defined communication and escalation protocols shall govern service and security issues, with agreed remediation timelines proportionate to severity. Persistent failure to meet security or service obligations shall trigger a formal remediation plan and may, for unresolved material breaches, lead to suspension or termination of the relationship (SOC 2 CC9.2).
13. Supplier Offboarding and Termination
On termination or expiry of a Supplier relationship, a documented offboarding process shall be completed: (a) all Company and customer data shall be returned in a usable format and/or securely destroyed, with the Supplier providing written certification of deletion, within 30 days; (b) all Supplier access to Company systems, accounts, credentials, VPNs, and physical premises shall be revoked promptly and verified; (c) any Company-owned assets or keys held by the Supplier shall be recovered or rotated; (d) surviving obligations of confidentiality and data protection shall be confirmed; and (e) the Supplier shall be removed from the active inventory. For Tier 1 Suppliers, completion of offboarding shall be reviewed and signed off by Vikram Patel .
14. Policy Compliance, Review and Update
Compliance with this Policy is mandatory for all personnel who engage or manage Suppliers. Violations may result in disciplinary action up to and including termination of employment. Vikram Patel is responsible for monitoring compliance, and the supplier-security programme shall be internally audited at least annually. This Policy shall be reviewed at least annually, and additionally following significant supplier-related incidents, regulatory change, or material changes to the supply chain. The next scheduled review date is [Review Date].
This Supplier & Third-Party Security Policy has been approved by the management of Acme Technologies Pvt Ltd and is effective from [Effective Date].
Approved by (CISO / CxO)
Approver name (CISO / CxO)
______________________
Policy Owner / TPRM Lead
Vikram Patel
______________________