Templates
Vendor Management
Vendor Cybersecurity Checklist
🔒

Vendor Cybersecurity Checklist

1
Identify the vendor and its level of access to data
2
Evaluate the vendor's history and reputation in the market
3
Verify if vendor has a designated security officer or team
4
Review the vendor's Infrastructural Security Measures
5
Assess vendor's policies on data encryption at rest and in transit
6
Check for vendor's adherence to security certifications and compliance requirements
7
Evaluate vendor's incident response plans
8
Approval: Incident Response Plans Review
9
Check the vendor's processes for software updates and vulnerability patching
10
Verify Vendor's employee training on cybersecurity
11
Review vendor's security audit history and reports
12
Approval: Audit History Review
13
Check the vendor's data backup and recovery plans
14
Assess whether vendor allows access to third parties
15
Analyze vendor's policy for secure disposal of data
16
Review the vendor's privacy policy and terms of service
17
Approval: Privacy Policy Review
18
Draft a contract highlighting security expectations from Vendor
19
Ascertain financial implications of breach
20
Finalize and sign contract with vendor