Could someone provide insights on the latest industry trends and best practices for incorporating information security provisions in contracts with third-party vendors and suppliers, including cloud service providers, especially when our company shares sensitive data?  Also, if there are any process improvement ideas for contract reviews, that would also be helpful.  Thank you.

856 viewscircle icon1 Upvotecircle icon4 Comments
Sort by:
Senior Manager in Softwarea year ago

First, specify security requirements like encryption standards, access controls and incident response. Include clauses for compliance with relevant regulations and regular security assessments or audits. It's also crucial to add a data breach notification clause that outlines how quickly vendors must inform you of breaches and their mitigation steps. For contract reviews, create a standardized checklist for security provisions to streamline the process and ensure consistency. Involving your legal and IT security teams early can help identify potential issues.

Manager, Cybersecurity in Travel and Hospitalitya year ago

I would highlight data handling and destruction policies, strict SLA’s, automated contract review alerts. For cloud, especially for cloud adopting CSA STAR is good one to consider for your requirements.

Lightbulb on2 circle icon2 Replies
no titlea year ago

Thank you Pradeep Reddy Sama.

Lightbulb on1
no titlea year ago

Happy to have conversations around the TPRM topic anytime.

Content you might like

Increase86%

Decrease13%

Reset when forgetting15%

Change upon expiry47%

Maintain & secure password lists25%

Being worried about phishing11%

Other (please comment)

View Results