ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Supplier Risk Assessment

Supplier Risk Assessment

1. Purpose

The Supplier Risk Assessment is used to identify, evaluate, and manage information-security, privacy, operational, business, and technology risks arising from suppliers, vendors, contractors, service providers, consultants, and other third parties.

The assessment helps the organization determine:

  • What services the supplier provides
  • What information and systems are involved
  • What level of access the supplier requires
  • How critical the supplier is to the business
  • What security threats and vulnerabilities may exist
  • What controls are required
  • Whether the supplier risk is acceptable
  • What additional risk treatment is required
  • How the supplier should be monitored and reassessed

Core Principle

Supplier → Service → Information → Access → Dependency → Threat → Vulnerability → Impact → Risk → Controls → Treatment → Residual Risk → Approval → Monitoring


2. When to Perform a Supplier Risk Assessment

A Supplier Risk Assessment should be performed when:

  • A new supplier is being onboarded
  • A supplier will access company systems
  • A supplier will access customer or personal data
  • A supplier will process confidential or restricted information
  • A supplier provides a critical business service
  • A supplier provides cloud or hosting services
  • A supplier requires production or privileged access
  • A supplier handles source code or security information
  • A supplier uses subprocessors
  • A major service or contract changes
  • A significant security incident occurs
  • The supplier’s ownership or operating location changes
  • Data location changes
  • A supplier introduces a new technology or AI service
  • The supplier is due for periodic reassessment

The frequency should be risk-based rather than identical for every supplier.


3. Supplier Risk Assessment Information

FieldDetails
Assessment ID
Supplier ID
Supplier Name
Supplier TypeVendor / SaaS / Cloud / Consultant / Contractor / Other
Service/Product
Business Owner
Supplier Owner
Department
Assessment Date
Assessment TypeInitial / Periodic / Triggered
Previous Assessment
CriticalityLow / Medium / High / Critical
Assessment StatusDraft / In Review / Approved / Action Required

4. Supplier and Service Description

Document what the supplier actually does for the organization.

ItemDetails
Service Description
Business Purpose
Business Process Supported
Primary Users
Service Location
Data Processing Location
Service Dependency
Expected Availability
Contract Period
Critical Business DependencyYes / No
Alternative Supplier AvailableYes / No
Exit/Migration Plan AvailableYes / No

Example

Supplier: AWS

Service: Cloud infrastructure

Business Process: Production SaaS platform

Information: Customer information, application data, logs and configuration data

Dependency: High

Alternative: Migration to another cloud provider would require significant planning and technical effort.

This information supports the determination of supplier criticality and risk.


5. Information and Data Assessment

Identify what information the supplier can access, receive, process, store, or transmit.

Information TypeApplicable?ClassificationDescription
Public Information☐Public
Internal Information☐Internal
Confidential Information☐Confidential
Restricted Information☐Restricted
Customer Information☐
Personal Data☐
Financial Information☐
Authentication Information☐
Source Code☐
Security Information☐
Intellectual Property☐

Assessment Questions

  1. What information does the supplier receive?
  2. What information does the supplier store?
  3. What information does the supplier process?
  4. Can the supplier modify the information?
  5. Can the supplier delete information?
  6. Is customer information involved?
  7. Is personal data involved?
  8. Is regulated information involved?
  9. Is information transferred internationally?

6. Supplier Access Assessment

Identify the access required by the supplier.

Access TypeRequired?Details
No system access☐
User application access☐
VPN/Remote access☐
Cloud access☐
Production access☐
Database access☐
Source-code access☐
Security-tool access☐
Administrative access☐
Privileged access☐
API access☐
Physical access☐

Access Risk Considerations

Assess:

  • Least privilege
  • Named individual accounts
  • MFA
  • Privileged access controls
  • Access approval
  • Access logging
  • Temporary access
  • Access review
  • Access revocation
  • Emergency access

7. Supplier Criticality Assessment

Determine how important the supplier is to business operations.

Consider:

  • Impact of supplier failure
  • Dependency on supplier availability
  • Customer impact
  • Information-security impact
  • Privacy impact
  • Regulatory impact
  • Financial impact
  • Operational impact
  • Recovery requirements
  • Availability of alternatives
  • Migration complexity

Example Classification

CriticalityTypical Characteristics
LowLimited business impact and no sensitive information
MediumImportant business service or confidential information
HighSignificant business dependency or sensitive information
CriticalFailure could materially affect critical operations, customers, security, or regulatory obligations

The organization should define its own detailed criticality criteria.


8. Threat Assessment

Identify credible threats associated with the supplier.

ThreatApplicable?Description
Unauthorized access☐
Credential compromise☐
Malware/ransomware☐
Data breach☐
Insider threat☐
Supplier employee error☐
Service outage☐
Cyberattack☐
Vulnerability exploitation☐
Subprocessor failure☐
Data loss☐
Unauthorized data disclosure☐
Supply-chain compromise☐
Physical disruption☐
Regulatory/legal issue☐
Fraud☐

9. Vulnerability / Weakness Assessment

Document weaknesses that could increase supplier risk.

Examples:

  • No MFA
  • Excessive privileges
  • Shared accounts
  • Weak access controls
  • Lack of security monitoring
  • Unsupported software
  • Poor vulnerability management
  • No independent assurance
  • Weak incident notification
  • No tested BCP/DR
  • Unclear data retention
  • Uncontrolled subprocessors
  • Unclear data location
  • Weak contractual security requirements
  • No secure deletion process
  • Lack of security testing

10. Impact Assessment

Assess the potential consequences if the supplier’s service or security controls fail.

Impact AreaRatingExplanation
ConfidentialityLow / Medium / High / Critical
IntegrityLow / Medium / High / Critical
AvailabilityLow / Medium / High / Critical
PrivacyLow / Medium / High / Critical
Customer ImpactLow / Medium / High / Critical
Regulatory ImpactLow / Medium / High / Critical
Financial ImpactLow / Medium / High / Critical
Operational ImpactLow / Medium / High / Critical
Reputation/Trust ImpactLow / Medium / High / Critical

11. Likelihood Assessment

Estimate the likelihood that the identified risk scenario could occur.

RatingExample Description
LowUnlikely under current conditions
MediumPossible and reasonably foreseeable
HighLikely or significant exposure exists
CriticalVery high likelihood or exposure requiring immediate attention

The organization should use its approved risk methodology where one exists.


12. Inherent Risk

Inherent risk represents the risk before considering existing controls or additional treatment.

A simple risk model may be:

Risk = Likelihood × Impact

LikelihoodImpactInherent Risk
LowLowLow
LowHigh

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *