Secure Vendors. Protected Value Chain.
VENDOR MANAGEMENT
At Assertiva, we recognize that our vendors and strategic partners are a fundamental part of our security chain. This policy summarizes our principles for protecting the confidentiality, integrity, and availability of shared information.
Current Version · Aligned with ISO/IEC 27001:2022 · Controls A.5.19 – A.5.23
CIA
Confidentiality · Integrity · Availability
A.5.19
ISO Control - Information security in supplier relationships
100%
Critical vendors subject to risk assessment
360°
Continuous monitoring throughout the lifecycl
Commitment
Security from the first point of contact
Prior Risk Assessment
Before onboarding any vendor, we evaluate the risks associated with the service and the required level of access.
Contractual Requirements
We define security and confidentiality clauses in contracts and agreements prior to the start of any activities.
Periodic Monitoring
We continuously verify compliance with security conditions and agreed-upon SLAs.
Incident Management
We have procedures in place to manage security incidents involving third parties.
Access Control
We apply the principle of least privilege to protect information assets against third-party access.
Secure Contract Termination
We manage the return or secure deletion of information upon the conclusion of any contractual relationship.
FORMAL PROCESS
Structured Vendor Management
Criticality Classification
Security Assessment
Continuous Review of Changes
Updated Registry
Secure Offboarding
Obligations
What We Expect from Our Vendors
Comply with Policies
Adhere to Assertiva's current information security requirements and policies.
Protect Assets
Safeguard the information and assets accessed during the contractual relationship.
Report Incidents
Promptly notify us of any security event or incident that may affect the services.
Communicate Changes
Maintain active communication regarding any changes that could impact service security.
Culture
Continuous Awareness
Security as a Shared Responsibility
We promote information security training and awareness programs for both our internal employees and the third parties interacting with our processes and systems. Security is not just technology — it is culture.