Vendor, Consultant, and Contractor Agreements and Controls
External parties such as vendors, consultants, and contractors from outside the organization might also have access to the organization's IT environment and internal information.
4 slides · 1 min read · Domain 1
It is important for the organization to create procedures and processes that properly constrain and distinguish access by non-employees.
Some tools the organization may consider for these purposes:
DISTINCT RESTRICTED ACCOUNTS
External parties might be granted differentiated accounts from other users; these accounts might provide limited access or convey additional audit trail information.
DISTINGUISHING IDENTIFICATION
Identity and/or access badges for non-employee personnel might be very noticeably different than employee badges, such as having a distinctly different color or shape.
CONTRACTUAL PROTECTIONS
The organization should protect itself from harm done by external parties that the organization has granted (even limited) access to; the contract between parties can stipulate the form of protection
ESCORT REQUIREMENTS necessary for accomplishing this (often monetary). This protection can take the form of cash payments for failing to External parties might require constant agree to terms, as requirements for the monitoring, either via surveillance or external party to maintain the appropriate continually in the presence of an employee insurance policies (in professional services, of the organization.
this is often addressed by errors and omissions policies), or as an express transfer of liability (where allowed by law).
As with internal personnel, external personnel should be required to sign non-disclosure agreements, acceptable use policies and, in some cases, go through internal training to ensure they are also aware of the sensitivity of information and the handling policies every person is required to uphold who accesses the information or information systems.
