A.5.19 Information Security in Supplier Relationships
1. Objective and Risk Management Framework
anDREa defines and implements strict processes to manage the information security risks associated with utilizing third-party vendor products, cloud systems, and external services. This lifecycle framework satisfies ISO/IEC 27001 Annex A.5.19 and aligns with NIS 2 Directive supply chain security mandates by enforcing baseline security requirements, active performance monitoring, and rigorous data protection checks across our entire vendor network.
2. Supplier Lifecycle and Registration Principles
To prevent third-party vulnerabilities from impacting the myDRE platform, all suppliers must complete a structured onboarding and evaluation process governed by these core components:
2.1 Supplier Typing and Security Baselines
- Classification Framework: anDREa maintains an explicit Types of Suppliers master specification. This standard defines the mandatory baseline security criteria, technical certifications (e.g., ISO/IEC 27001, SOC 2), and compliance frameworks required for each vendor category based on their operational risk.
- Criticality Mapping: The central vendor registry explicitly flags critical suppliers in anDREa Supplier List; vendors whose services directly support core myDRE platform hosting, identity boundaries, or health-data research continuity.
2.2 Formal Documentation Dossiers
The Business Manager maintains a dedicated, secure folder for each vendor within our cloud repository. This dossier contains all contractual and compliance evidence, including:
- Signed Supplier Master Service Agreements (SLAs).
- Executed Data Processing Agreements (DPAs) satisfying GDPR mandates.
- Signed Non-Disclosure Agreements (NDAs).
- Active independent security certificates, audit reports, and vulnerability statements.
2.3 Comprehensive Data Classification
Before any integration or tool onboarding occurs, the data accessible to the supplier or application is explicitly classified into one of two operational categories:
- Sensitive: Access to internal system configurations, source code, employee identities, or client tenant spaces. This triggers enhanced compliance scrutiny and continuous monitoring.
- Non-Sensitive: Limited to generic business administration or non-critical operational tools.
3. Continuous Monitoring and Supplier Reviews
Supplier tracking relies on automated operational schedules to ensure ongoing compliance:
- Scheduled Annual Reviews: All onboarded vendors (with specific exceptions managed under Annex A.5.20) undergo a formal Supplier Review at least annually. This review evaluates the vendor's performance, tests their compliance against the baseline criteria in the Types of Suppliers standard, and verifies that their external certifications remain active.
- Monthly Administrative Maintenance: To ensure data integrity, the Business Manager executes scheduled monthly checks across the vendor ecosystem. Updates to contacts, contract renewals, or certificate refreshes are tracked live within the master vendor registry.
- Operational Control Integration: These oversight loops are scheduled and tracked within anDREa Supplier List to maintain complete audit traceability.
4. Operational Controls for Supplier Access
When a third-party vendor, external contractor, or consultant interacts with anDREa's systems, they must adhere to the following strict operational controls:
- Granular Identity Provisioning: External personnel are never granted shared or persistent credentials. Individual identities are provisioned, tracked, and bounded within the anDREa People HR portal in strict accordance with A.05.15 - Access control and the Principle of Least Privilege.
- Mandatory Security Awareness Training: If an external partner or contractor is embedded within anDREa's operations (e.g., outsourced software engineering or platform support), they must complete our internal Information Security and Data Protection Training (responses) curriculum prior to system activation.
- Mandatory Incident Escalation: All suppliers are contractually and procedurally required to report any suspected or validated information security incident immediately upon discovery. These escalations must follow our standard incident response paths as detailed in A.05.26 - Response to information security incidents.