Answer yes if your organisation ensures that all third parties with access to client data have a formal agreement in place that contains appropriate security clauses including the right to audit and mandatory adherence to appropriate security policies.
It is important that in your supplier contracts you have defined a level of information security requirements that your suppliers must meet, and that you have imposed audit rights over the supplier to make sure you can get assurance that the requirements are being met.
The contract should also mandate that the supplier has to ‘trickle down’ these requirements onto any of their suppliers who have access to your data.
The following is a list of example security clauses that may need to be included in your contracts:
Risk Ledger recommends that you use a solicitor to ensure all of your supplier contracts contain the relevant clauses to ensure that all risks (security and other risks) are minimised.
Risk Ledger helps you to make sure your suppliers comply with your information security requirements, to find out more contact us at support@riskledger.com!
If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.