N.1.16 Ensuring information security in agreements with suppliers
Control Overview
This control mandates that information security expectations, roles, and liabilities are formally codified within legally binding agreements with suppliers. To eliminate security incidents born out of ambiguous vendor relationships, contracts must explicitly detail security requirements—such as data classification rules, mandatory incident notification timelines, sub-contracting restrictions, and right-to-audit clauses. For large-scale commodity cloud providers where terms cannot be altered, the organization must run a formal gap analysis and execute a management-backed risk acceptance process to ensure all supply chain risks are completely understood and managed.
Applicability Note: This control is fully applicable to the anDREa platform and explicitly governs its contracts with hyper-scale cloud hosts, software vendors, and downstream development dependencies.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, distinguishing between customizable third-party contracts and non-negotiable enterprise vendor frameworks.
For bespoke vendors, we embed standard security clauses directly into our master agreements. For non-negotiable upstream enterprise dependencies (such as Microsoft and Google), anDREa follows a structured, auditable vetting process. Instead of blindly accepting standard terms, we execute a rigorous SIA Instructions and gap analysis to identify any delta between vendor guarantees and our strict security needs. Residual risks are formalized, submitted to senior leadership for explicit risk acceptance, and continuously monitored through the systematic review of vendor SOC 2 Type II reports and public vulnerability bulletins.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.20 - Addressing information security within supplier agreements | Requires relevant information security requirements to be established and agreed upon with each supplier based on data access. |
| ISO/IEC 27001 | A.05.21 - Managing information security in the information and communication technology (ICT) supply chain | Dictates risk-management procedures for analyzing upstream software, service delivery, and platform-as-a-service risks. |
| Operational Governance | SIA & Supplier Gap Analysis Logs | Technical delta reviews tracking standard hyper-scaler guarantees against internal anDREa compliance baselines. (anDREa Supplier List) |
| Executive Risk Matrix | Management Risk Acceptance Sign-Offs | Documented audit trails showing executive review and formal approval for any accepted residual risks associated with standard terms. (anDREa Supplier List) |
| Continuous Assurance | SOC 2 type II | Saved analysis records of external supplier SOC 2 Type II reports, verification notes, and tracked upstream security bulletin outputs. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Security clauses are legally defined for custom vendors, and hyper-scaler exceptions are governed by strict gap analyses and active risk acceptances. Continuous Improvement: Ensure that all documented "exceptions" or residual risks on the risk register maintain explicit links to active, signed management risk acceptances and traceable periodic review actions.