Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Business Manager

previous version on gdrive

A.5.20 Addressing Information Security within Supplier Agreements

1. Objective and Agreement Principles

anDREa ensures that relevant information security obligations are established, legally formalized, and agreed upon with each third-party vendor before granting access to organizational assets, cloud frameworks, or source code repositories. This policy satisfies ISO/IEC 27001 Annex A.5.20 and supports the risk governance mandates enforced by the NIS 2 Directive.

Information security requirements are mapped to the specific supplier relationship (A.05.19 - Information security in supplier relationships). Depending on the classification and criticality of the vendor, anDREa requires the inclusion of the following structural terms within all formalized contracts and Data Processing Agreements (DPAs):

  • Data Scope & Access Mechanics: A precise description of the information assets to be processed or accessed, alongside authorized technical transmission methods and interface rules.
  • Classification Alignment: Alignment with anDREa’s data classification tiers as defined in A.05.12 - Classification of information and A.05.13 - Labelling of information.
  • Legal and Regulatory Compliance: Binding commitments to meet statutory mandates, specifically including data protection legislation (GDPR), intellectual property (IP) protections, copyrights, and enforceable confidentiality clauses.
  • Policy Enforcement: Mandatory adherence to specific anDREa security policies relevant to the contract, such as logical access boundaries and formal change windows.
  • Incident & Change Notification: Contractual obligations requiring the supplier to report any suspected or validated information security incident immediately, alongside mandatory alerts regarding major changes to the supplier's internal security policies.
  • Personnel Authorization: An explicit directory of the supplier's personnel authorized to handle anDREa data, or an enforceable standard operating procedure governing how the supplier provisions, tracks, and revokes these personnel authorizations.
  • Designated Security Points of Contact (PoC): Up-to-date contact channels for the supplier's security officers to streamline emergency escalation.
  • Sub-Contracting & Supply Chain Governance: Strict regulations governing the supplier's right to utilize sub-contractors, including the mandate that all core security controls must cascade down to downstream vendors.
  • Right to Audit: Explicit provisions granting anDREa the right to audit the supplier’s internal operational processes, codebase security, and physical or logical controls related to the execution of the agreement.

2. Termination and Offboarding Framework

The terms, conditions, and close-out windows for terminating a supplier agreement or managing major structural revisions are hardcoded within the individual agreement itself. During the wind-down or transition of any supplier relationship, the Business Manager executes a formal offboarding sequence.

2.1 Critical Supplier Offboarding Mechanics

If the relationship being altered or terminated involves a critical supplier (such as core cloud architecture or primary pipeline tooling, see anDREa Supplier List), the Management Team must execute a targeted SIA Instructions. This assessment analyzes the operational risks, availability drops, or configuration gaps introduced by decommissioning the vendor and outlines necessary transition mitigations.

2.2 Standard Supplier Offboarding Checklist

To prevent data leakage, residual access, or supply chain gaps, the following three-step offboarding sequence is mandatory:


┌────────────────────────────────────────────────────────┐
│ 1. Complete Logical Access Revocation                  │
│ ───► Purge accounts, federated tokens, and IAM roles   │
└───────────────────────┬────────────────────────────────┘
                      │
                      ▼
┌────────────────────────────────────────────────────────┐
│ 2. Formal Data Erasure & Attestation                   │
│ ───► Verify deletion of shared information assets      │
│ ───► Secure signed confirmation of erasure from vendor │
└───────────────────────┬────────────────────────────────┘
                      │
                      ▼
┌────────────────────────────────────────────────────────┐
│ 3. Stakeholder Notification                            │
│ ───► Inform internal employees, partners, and clients  │
│ ───► Adjust platform documentation and baseline logs   │
└────────────────────────────────────────────────────────┘

All finalized termination artifacts, impact reviews, and signed erasure certifications are archived in the vendor's dedicated dossier, accessible via the master supplier list.


3. Policy Exceptions & Compensating Controls

anDREa recognizes that two specific scenarios exist where enforcing our custom, standardized security terms can be structurally difficult. In these instances, the following governance loops are enforced:

Exception A: Legacy Agreements

For contracts and vendor agreements finalized before the implementation of this policy, introducing additional technical requirements or custom clauses mid-contract may be legally challenging.

  • Remediation Path: The Business Manager initiates a formal conversation with the vendor to append a security addendum.
  • Escalation Path: If the supplier is uncooperative, anDREa executes an ad-hoc risk assessment. Based on the risk rating, the Management Team determines whether to accept the residual operational risk or initiate steps to transition to an alternative, compliant supplier.

Exception B: Non-Negotiable Hyperscale Providers

anDREa utilizes critical, globally distributed platform applications hosted by industry hyperscalers (such as Microsoft Azure and Google Workspace) that enforce standard, non-negotiable enterprise service agreements.

  • Compensating Control: To verify the ongoing security posture of these platforms, the Management Team executes a yearly independent audit review. anDREa collects, evaluates, and documents the supplier's official SOC 2 type II reports and matching security assertions.
  • Oversight Integration: The analysis of these SOC 2 Type II reports, verification of control effectiveness, and any required architectural adjustments are documented within the Periodic Security Controls portal and tracked inside the SOC 2 type II governance directory.