N.1.15 Protection of information in cooperation with suppliers
Control Overview
This control requires the organization to establish a robust third-party risk management framework to evaluate and monitor the cybersecurity posture of its suppliers. To prevent security incidents caused by a compromised upstream dependency, the organization must ensure that all third-party services and products meet its internal information security requirements. This involves conducting rigorous pre-onboarding assessments, categorizing suppliers by criticality, establishing legally binding security and privacy terms, and conducting periodic reviews to manage ongoing supply chain risks.
Applicability Note: This control is fully applicable to the anDREa platform, particularly across critical cloud infrastructure, SaaS vendors, and development sub-processors.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement is seamlessly driven by our ISO/IEC 27001-based ISMS, treating supply chain security as an extension of our own internal risk posture.
anDREa manages third-party risk through a structured lifecycle. Before onboarding any vendor, we conduct a formal SIA Instructions to understand data flows, architecture, and potential vulnerabilities. Suppliers are added to a centralized inventory and assigned a criticality level based on their access to systems and data. High-criticality vendors must provide formal security assurances (e.g., ISO 27001 certifications, SOC 2 reports) and execute comprehensive Data Processing Agreements (DPAs) and Non-Disclosure Agreements (NDAs). Supplier access to our environments is strictly governed by our core identity management framework, ensuring third-party accounts are monitored and bounded by least-privilege principles.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.19 - Information security in supplier relationships | Mandates requirements for mitigating the information security risks associated with the use of supplier products and services. |
| Pre-Onboarding Evaluation | SIA Register | The mandatory risk assessment blueprint used to analyze and approve a vendor's technical controls prior to engagement. |
| Centralized Inventory | anDREa Supplier List | The master ledger tracking all active third parties, mapped by their criticality classification and operational dependencies. |
| Vendor Dossiers | Supplier Folders | Centralized audit repositories containing signed contracts, DPAs, NDAs, and validated external security certifications. |
| Operational Reviews | anDREa Supplier List | Documented evaluations tracking ongoing vendor performance, continuous risk ratings, and certification renewals. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Supplier impact assessments, contracts, dossiers, and access boundaries are fully operationalized and managed. Continuous Improvement: To optimize readiness for upcoming NIS 2 audits, maintain an explicit cross-reference in your NIS 2 register that links critical suppliers directly to any designated "essential" or "important" service infrastructure dependencies.