graphgrc

VEN-02: Vendor Contracts & DPAs

Objective

Ensure vendors meet security and privacy obligations through contractual controls.

Description

Vendor contracts include security, privacy, and compliance requirements. Data Processing Agreements (DPAs) are executed with vendors processing customer data. Vendor compliance is monitored.

Implementation Details

Contract Requirements: All vendor contracts reviewed by legal and security. Include security standards, SLA, audit rights, termination clause.

DPAs: DPAs executed with any vendor processing customer personal data (GDPR requirement). Standard DPA template approved by legal.

SLA Monitoring: Monitor vendor SLAs for availability, incident notification, data deletion. Escalate breaches to vendor management.

Contract Repository: Central repository (DocuSign, Ironclad) for vendor contracts and DPAs. Track expiration and renewal dates.

Examples

Audit Evidence


Framework Mapping

SOC 2

GDPR


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.

Processes: