For the complete documentation index, see llms.txt. This page is also available as Markdown.

Supplier Security Requirements

Purpose

Suppliers must meet security requirements appropriate to the work they perform.

Supplier Security Controls

Suppliers may be required to provide:

  • security policy evidence

  • personnel checks

  • confidentiality commitments

  • access control compliance

  • secure development practices

  • incident notification process

  • insurance evidence

  • data handling compliance

  • audit cooperation

Supplier Access

Supplier access should be:

  • approved

  • limited

  • monitored

  • time-bound

  • removed promptly when no longer required

Last updated

Was this helpful?