Skip to main content

IT Service and Third Party Agreement Requirements

Source basis

Ported from reference/IT Service & 3rd Party Vendor Agreements.md in the legacy ISMS backup. Use this as the current maintained Markdown version and track operational records in core12-isms-management.

Guidelines when reviewing / approving an IT Service or 3rd Party agreement.

ClausePurpose
Scope of ServicesClearly define what the provider will deliver, including any access to systems, networks, or data.
Information Security RequirementsMandate compliance with your security policies, TISAX controls, and ISO/IEC 27001 principles.
Confidentiality and NDAsEnforce protection of sensitive information, including after contract termination.
Data Protection (GDPR if applicable)Require adherence to data protection laws; include a Data Processing Agreement (DPA) if handling personal data.
Access ControlDefine access limitations, authentication requirements, and least privilege principles.
Incident ReportingRequire prompt notification of any security incidents, breaches, or data leaks - with specified timelines.
Subcontracting RestrictionsPrevent unauthorized use of subcontractors or require written approval and similar compliance.
Right to Audit / ReviewGrant your company or its auditors the right to inspect the provider's controls or receive audit reports (e.g. ISO 27001, TISAX label).
Business Continuity & Disaster RecoverySpecify availability/recovery expectations if the vendor provides critical services.
Termination and Data Return/DestructionSet procedures for secure return or destruction of data and revocation of access at contract end.
Security Awareness & TrainingRequire provider personnel to be aware of security responsibilities.
Liability for BreachesDefine accountability, including consequences for non-compliance or breaches.