vStream Digital Media / ShineVR
Vendor Management Policy
Definitions
| Term | Definition |
|---|---|
| Company | means vStream Digital Media |
| ShineVR | means the ShineVR product developed and operated by vStream Digital Media |
| GDPR | means the General Data Protection Regulation |
| Responsible Person | means Andrés Pitt, CTO |
| Vendor | Any third-party supplier, service provider, contractor, or partner providing goods or services to the Company |
| Critical Vendor | Vendor with access to sensitive data, critical systems, or whose failure would significantly impact business operations |
| Data Processor | Vendor who processes personal data on behalf of the Company as Data Controller |
| Risk Classification | Assessment of vendor risk level (Low, Medium, High, Critical) based on data access and service criticality |
| Data Processing Agreement (DPA) | Contractual agreement defining data protection responsibilities between Company and vendor |
1. Policy Statement
vStream Digital Media recognises that third-party vendors are essential to business operations but also represent potential security, privacy, and operational risks. This Vendor Management Policy establishes a comprehensive framework for assessing, selecting, contracting with, and monitoring vendors to ensure they meet the Company's security, privacy, and operational requirements.
All vendors must be evaluated for security posture, data protection practices, and business continuity capabilities before engagement. Ongoing monitoring ensures vendors continue to meet requirements throughout the relationship lifecycle.
2. Purpose
The purpose of this policy is to:
- Establish consistent vendor assessment and selection criteria
- Ensure vendors meet appropriate security and privacy standards
- Protect Company and ShineVR data processed by vendors
- Ensure GDPR compliance for vendors processing personal data
- Define vendor risk classification and management requirements
- Establish ongoing vendor monitoring and review procedures
- Define vendor incident response and termination procedures
- Ensure business continuity through vendor resilience
- Maintain a comprehensive vendor inventory and risk register
3. Scope
This policy applies to:
- All third-party vendors providing services or products to the Company
- All vendors with access to Company or ShineVR systems, data, or facilities
- All vendors processing personal data on behalf of the Company
- Cloud service providers (including Google Cloud Platform)
- Software-as-a-Service (SaaS) providers
- Professional services firms
- Contractors and consultants
- Technology suppliers
- Business partners with data sharing arrangements
This policy applies throughout the vendor lifecycle:
- Vendor identification and selection
- Vendor assessment and due diligence
- Contract negotiation and execution
- Ongoing vendor management and monitoring
- Vendor performance review
- Contract renewal or termination
- Vendor offboarding
4. Vendor Risk Classification
4.1 Risk Classification Criteria
All vendors are classified based on:
- Data Access: What type and volume of Company/customer data can vendor access?
- Service Criticality: How critical is the vendor's service to business operations?
- System Access: What level of access does the vendor have to Company systems?
- Regulatory Impact: Does vendor processing affect regulatory compliance?
- Financial Impact: What is the financial impact of vendor failure or breach?
- Reputational Impact: What reputational damage could a vendor incident cause?
4.2 Risk Classifications
| Risk Level | Definition | Examples | Assessment Requirements |
|---|---|---|---|
| Critical | Access to sensitive personal data, critical systems, or service failure causes major business disruption | Google Cloud Platform, primary payment processor, core application vendors | Comprehensive security assessment, penetration testing requirements, executive approval, detailed DPA, annual reassessment, continuous monitoring |
| High | Access to confidential business data, important systems, or service failure causes significant disruption | Email/collaboration platforms (Google Workspace), customer communication tools (Slack), database vendors | Detailed security assessment, security certifications required, CTO approval, DPA if processing personal data, annual review, performance monitoring |
| Medium | Limited data access, moderate system access, or service failure causes moderate disruption | Development tools, project management software, analytics platforms | Standard security assessment, basic security documentation, CTO approval, DPA if processing personal data, bi-annual review |
| Low | No sensitive data access, minimal system access, service failure has minimal impact | Office supplies, marketing services (no data access), generic tooling | Basic vendor assessment, standard contract terms, manager approval, annual review if multi-year contract |
4.3 Risk Classification Review
- Initial risk classification assigned during vendor selection
- Risk classification reviewed annually or when vendor services change
- Vendor may be reclassified if risk profile changes
- Higher risk classification triggers enhanced controls
- Risk classification documented in vendor register
5. Vendor Selection And Assessment
5.1 Vendor Identification
Prior to Engaging Any Vendor:
- Business need clearly defined and documented
- Alternative solutions evaluated (build vs. buy, multiple vendor options)
- Budget and resource requirements assessed
- Stakeholder requirements gathered
- Compliance and regulatory requirements identified
5.2 Vendor Assessment Process
Step 1: Initial Assessment — Evaluate vendor based on: prior knowledge (Company's previous experience or industry reputation); financial stability; market position; references; service fit; geographic location (preference for EU-based vendors for data residency); pricing model (avoid "free" products that monetise through data resale).
Step 2: Security Assessment — For Medium, High, and Critical risk vendors:
- Security Documentation Review: Information security policies and procedures; data protection and privacy policies; incident response procedures; business continuity and disaster recovery plans; security awareness training programmes; vulnerability management processes; access control procedures.
- Security Certifications: Required for High/Critical vendors: SOC 2 Type II, ISO 27001, or equivalent. Preferred certifications: ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, PCI DSS (if processing payment data), CSA STAR (for cloud providers). Certifications must be current; certification audit reports reviewed if available.
- Technical Security Controls: Encryption at rest and in transit; access control and authentication mechanisms; network security and segmentation; vulnerability management and patching; security monitoring and logging; backup and recovery capabilities; physical security of data centres (for infrastructure providers).
Step 3: Data Protection and Privacy Assessment — For vendors processing personal data:
- Data Processing Practices: Types of personal data processed; purpose and legal basis for processing; data storage locations and residency; data retention and deletion practices; sub-processor arrangements; cross-border data transfers.
- GDPR Compliance: GDPR compliance programme; Data Protection Officer (DPO) appointed if required; data subject rights support; breach notification procedures (within 72 hours); data protection by design and default; Privacy Impact Assessments for high-risk processing.
- Privacy Certifications: ISO 27701 (Privacy Information Management); EU-US Data Privacy Framework certification (if US-based); Privacy Shield successor mechanisms; national privacy certifications.
Step 4: Operational Assessment
- Service Level Agreements (SLAs): Availability and uptime guarantees; performance metrics; response and resolution times for issues; penalties for SLA breaches; scheduled maintenance windows.
- Business Continuity: Business continuity and disaster recovery plans; backup and recovery procedures; redundancy and failover capabilities; incident response capabilities; financial stability and viability.
- Support and Maintenance: Support availability (24/7, business hours, time zones); support channels (phone, email, portal); escalation procedures; account management; professional services availability.
Step 5: Contract and Legal Review
- Standard Contract Terms: Scope of services clearly defined; pricing and payment terms; contract term and renewal provisions; termination clauses and notice periods; liability and indemnification; intellectual property rights; confidentiality obligations.
- Security and Privacy Clauses: Data Processing Agreement (DPA) for vendors processing personal data; security controls and standards requirements; right to audit vendor security practices; breach notification obligations; data return and deletion upon termination; sub-processor notification and approval requirements.
- Compliance Requirements: Regulatory compliance obligations; industry standards compliance; legal jurisdiction and governing law (prefer EU/Irish law); compliance with Company policies.
Step 6: Risk Assessment and Approval — Complete vendor risk assessment documenting: risk classification (Low, Medium, High, Critical); key risks identified; mitigating controls; residual risk level; compensating controls if needed.
Approval Requirements:
- Low risk: Department manager approval
- Medium risk: CTO approval
- High risk: CTO approval with documented risk assessment
- Critical risk: CTO and CEO approval with comprehensive risk assessment
5.3 Vendor Assessment Documentation
All vendor assessments documented including: vendor name and contact information; service description and business purpose; risk classification and justification; security assessment results; compliance verification; references checked; contract review notes; risk assessment summary; approval signatures and dates; all documentation retained in vendor management system.
6. Vendor Selection Principles
6.1 Security-First Approach
Mandatory Principles:
- Security is primary consideration in vendor selection
- Vendors without adequate security controls are rejected regardless of cost savings
- "Free" services are avoided if they monetise user data (e.g., selling data to third parties)
- Security certifications (SOC 2, ISO 27001) strongly preferred for critical vendors
Example Applications:
- Google Analytics not used in ShineVR applications (avoid free products that track user behaviour)
- Paid security tools preferred over free alternatives with data sharing
- Open-source solutions acceptable if security can be verified and maintained
6.2 EU Preference
Data Residency Preference:
- EU-based vendors preferred for services processing personal data
- Non-EU vendors acceptable only if: adequate data protection mechanisms in place (Standard Contractual Clauses); data processing occurs in EU data centres; GDPR compliance demonstrated; no alternatives meeting requirements
Current EU Vendors:
- Primary infrastructure: Google Cloud Platform (EU data centres)
- Email and productivity: Google Workspace
- Internal communication: Slack
6.3 Compatibility and Integration
Technical Compatibility: Vendor solutions must integrate with existing systems; APIs and integration methods assessed; data import/export capabilities verified; compatibility with Google Cloud Platform preferred.
Operational Compatibility: Vendor support hours align with Company needs; vendor culture and values align with Company; communication and language capabilities adequate.
6.4 Vendor Reputation and Stability
Reputation Assessment: Industry reputation and customer reviews; security incident history researched; data breach history reviewed; customer references checked; media coverage and public perception.
Financial Stability: Financial health assessed for critical vendors; business viability for multi-year commitments; merger/acquisition risk considered; backup vendor identified for critical services.
7. Contractual Requirements
7.1 Data Processing Agreements (DPA)
Mandatory Requirement: All vendors processing personal data must execute a Data Processing Agreement
DPA Must Include:
- Description of processing activities and purposes
- Types of personal data and categories of data subjects
- Duration of processing
- Obligations of data processor (vendor): process data only on documented instructions; ensure confidentiality of personnel; implement appropriate security measures; engage sub-processors only with prior authorisation; assist with data subject rights requests; notify breaches within 24 hours; delete or return data upon termination; submit to audits and provide information
- Company rights and obligations as data controller
- International data transfer mechanisms (if applicable)
- Liability and indemnification for data breaches
Standard Contractual Clauses (SCCs):
- Required for transfers to vendors outside EEA
- Use EU Commission approved SCCs
- Additional safeguards for transfers to certain countries
7.2 Security Requirements in Contracts
Mandatory Security Clauses:
- Vendor must maintain appropriate technical and organisational security measures
- Specific security controls required (encryption, access control, monitoring, etc.)
- Security standards to be maintained (ISO 27001, SOC 2, etc.)
- Regular security assessments and penetration testing (for critical vendors)
- Vulnerability disclosure and patching timelines
- Security incident notification obligations (within 24 hours)
- Company right to audit vendor security practices
- Security breach liability and indemnification
7.3 Audit Rights
Company Rights to Audit:
- Annual right to audit vendor security and privacy practices
- Right to review vendor security documentation
- Right to request third-party audit reports (SOC 2, ISO 27001)
- Right to conduct on-site audits for critical vendors (with reasonable notice)
- Right to engage third-party auditors
- Vendor must cooperate with audits and provide requested information
7.4 Sub-Processor Management
For vendors who use sub-processors:
- Vendor must notify Company of all sub-processors
- Company right to object to sub-processors
- Sub-processors must meet same security and privacy standards
- Vendor remains liable for sub-processor actions
- List of current sub-processors provided at contract signing
- Changes to sub-processors require advance notification (30 days minimum)
7.5 Termination and Data Return
Contract Termination Provisions:
- Clear termination clauses and notice periods
- Transition assistance during termination period
- Data return or deletion obligations: vendor must return all Company data in usable format within 30 days; vendor must securely delete all Company data after return; vendor must certify deletion in writing
- Survival clauses (confidentiality, audit rights, liability)
8. Vendor Onboarding
8.1 Onboarding Process
Upon vendor selection and contract execution:
Step 1: Vendor Registration — Add vendor to vendor register/inventory; assign unique vendor ID; document vendor details (contact, services, risk level, contract dates); assign vendor owner within Company.
Step 2: Access Provisioning — Provision necessary system access (least privilege principle); create vendor user accounts or service accounts; configure access controls and permissions; enable multi-factor authentication if applicable; document all access granted.
Step 3: Security Configuration — Configure security settings per contract requirements; enable logging and monitoring for vendor activity; set up security alerts for vendor-related events; configure encryption for data shared with vendor; test security controls.
Step 4: Vendor Orientation — Provide vendor with relevant Company policies; security and privacy requirements review; incident reporting procedures; communication protocols and contacts; support and escalation procedures.
Step 5: Initial Performance Baseline — Establish performance metrics and KPIs; configure monitoring and reporting; schedule regular review meetings; define success criteria.
8.2 Vendor Documentation
Maintain comprehensive vendor documentation: vendor contact information and account managers; contract and DPA copies; security assessment results; risk assessment and approval documents; access permissions and credentials; integration documentation; escalation procedures; review and audit schedules.
9. Ongoing Vendor Management
9.1 Continuous Monitoring
Automated Monitoring:
- Security Monitoring: Keyword monitoring for vendor security incidents (security newsletters, CVE databases); vendor security posture monitoring via third-party services; system availability and performance monitoring; log analysis for unusual vendor activity.
- Performance Monitoring: Performance dashboards for critical vendors; SLA compliance tracking; service availability monitoring; response time and quality metrics; cost and usage tracking.
Manual Monitoring: Regular review of vendor security news and announcements; quarterly review of vendor security status; annual review of vendor certifications (renewal, expiration); periodic review of vendor financial stability.
9.2 Vendor Performance Reviews
Review Frequency Based on Risk:
- Critical vendors: Quarterly reviews
- High-risk vendors: Semi-annual reviews
- Medium-risk vendors: Annual reviews
- Low-risk vendors: Annual reviews (if multi-year contract)
Performance Review Includes: SLA compliance and performance metrics; security posture and incident history; data protection compliance; contract compliance; communication and support quality; cost effectiveness and value; business continuity preparedness; recommendations for continuation, renegotiation, or termination.
Review Documentation: Performance review meeting notes; metrics and KPIs analysis; issues and concerns identified; action items and remediation plans; decisions on contract renewal or changes.
9.3 Vendor Compliance Monitoring
Ongoing Compliance Verification:
- Security Certifications: Track certification expiration dates; request updated certificates upon renewal; verify certifications remain current; escalate if certifications lapse.
- Policy and Procedure Updates: Review updated vendor policies when published; assess impact of vendor policy changes; request clarification on significant changes; update internal documentation as needed.
- SLA and Contract Compliance: Monitor SLA adherence; track contractual obligations; document and escalate breaches; request remediation for non-compliance.
9.4 Vendor Relationship Management
Regular Communication: Scheduled review meetings (frequency based on risk level); quarterly business reviews for critical vendors; ad-hoc meetings for issues or changes; annual strategic planning sessions for key partners.
Relationship Optimization: Identify opportunities for improved service; negotiate better terms or pricing; expand or reduce services based on needs; provide feedback on vendor performance; collaborate on innovation and improvements.
Vendor Satisfaction: Ensure timely payment of invoices; provide clear requirements and feedback; maintain professional working relationship; recognise and appreciate good performance.
10. Vendor Security Incidents
10.1 Vendor Incident Notification
Vendor Obligations: Notify Company of security incidents within 24 hours; provide initial incident details (nature of incident; data potentially affected; number of individuals affected; actions taken by vendor; estimated timeline for resolution); provide regular updates during incident response; provide final incident report with root cause analysis.
Company Response: Log incident in Company incident register; assess impact on Company operations and data; activate incident response plan if necessary; coordinate with vendor on response actions; notify affected parties if required (customers, regulators); document all communications and actions.
10.2 Vendor Incident Assessment
Upon notification of vendor security incident:
Step 1: Initial Assessment (within 2 hours) — Classify incident severity (P1, P2, P3); determine impact on Company and ShineVR systems; identify data potentially compromised; assess regulatory notification requirements.
Step 2: Containment Actions — Disable vendor system access if necessary; rotate credentials and API keys; implement additional monitoring; isolate affected systems or data; prevent further data access or loss.
Step 3: Investigation and Remediation — Work with vendor to understand root cause; verify vendor's remediation actions; assess effectiveness of vendor response; determine if additional controls needed; consider long-term vendor relationship.
Step 4: Recovery and Post-Incident — Restore normal operations when safe; enhanced monitoring for 30 days; post-incident review with vendor; update risk assessment and controls; document lessons learned.
10.3 Breach Notification Obligations
If vendor incident affects personal data: Assess GDPR notification requirements within 24 hours; notify Data Protection Commission within 72 hours if required; notify affected data subjects if high risk; document decisions and rationale; maintain detailed records of breach response.
Vendor Liability: Vendor liable for breaches caused by their actions or negligence; indemnification clauses in contract apply; financial penalties and damages per contract; potential contract termination for serious breaches.
11. Vendor Termination And Offboarding
11.1 Termination Reasons
Vendor relationships may be terminated due to: contract expiration or non-renewal; poor performance or repeated SLA breaches; security breaches or non-compliance; business requirements change; better alternative vendor identified; vendor out of business or acquired; cost optimization; strategic realignment.
11.2 Termination Process
Step 1: Termination Decision and Notification — Document termination reason and approval; review contract termination clauses; provide required notice per contract (typically 30-90 days); communicate termination to vendor in writing; establish termination timeline and milestones.
Step 2: Transition Planning — Identify replacement vendor or alternative solution; plan data migration and service transition; assign transition responsibilities; establish transition timeline; test replacement solution.
Step 3: Data Return and Deletion — Request return of all Company data from vendor; verify data completeness and integrity; import data into replacement system; request certified deletion of all Company data; obtain written certification of deletion; verify deletion if possible (audit vendor's systems).
Step 4: Access Revocation — Revoke all vendor access to Company systems; delete vendor user accounts and service accounts; rotate credentials and API keys accessed by vendor; remove vendor from authentication systems; update firewall rules and network access controls.
Step 5: Documentation and Closure — Final vendor performance review; lessons learned documentation; update vendor register (mark as terminated); archive all vendor documentation; close out financial accounts; provide feedback to vendor (if appropriate).
11.3 Emergency Termination
For serious security breaches or emergencies: immediate access revocation without notice; rapid data return or deletion; accelerated transition to alternative vendor; legal consultation for contract disputes; regulatory notification if required.
12. Vendor Inventory And Register
12.1 Vendor Register Contents
Comprehensive vendor register maintained including: vendor name and legal entity; vendor contact information; service description and business purpose; risk classification (Low, Medium, High, Critical); contract dates (start, end, renewal dates); contract value; data processing role (processor, sub-processor, joint controller); personal data processed (types, categories, volumes); system access granted; security certifications; last assessment date and next review date; vendor owner within Company; status (active, inactive, terminated); notes and special considerations.
12.2 Register Maintenance
- Vendor register reviewed and updated quarterly
- Changes documented with dates and reasons
- Annual comprehensive review and cleanup
- Register accessible to CTO and relevant managers
- Register used for reporting and compliance demonstration
13. Special Vendor Types
13.1 Critical Infrastructure Vendors
Google Cloud Platform (Primary Infrastructure Provider): Comprehensive annual assessment; quarterly service review meetings; continuous monitoring of Google Cloud Status and security bulletins; leveraging Google's certifications (ISO 27001, SOC 2, etc.); regular review of Google Cloud compliance documentation; participation in Google Cloud security programmes; escalation procedures for critical issues; disaster recovery planning for Google Cloud outages.
Key Characteristics: Single-source dependency for infrastructure; critical to all ShineVR operations; extensive due diligence required; enhanced monitoring and relationship management.
13.2 SaaS Application Vendors
Examples: Google Workspace, Slack, GitHub/GitLab
Management Approach: Security assessment focused on data protection; review of vendor's security and privacy policies; verification of security certifications; user access management and provisioning; regular review of user licenses and usage; integration security (APIs, SSO); data export and portability planning.
13.3 Professional Services Vendors
Examples: External security consultants, auditors, legal advisors
Management Approach: Confidentiality agreements required; limited-time access to systems or data; supervised access where possible; background checks for sensitive work; work product ownership clearly defined; engagement terms and deliverables documented.
13.4 Open-Source Software
Approach to Open-Source: Open-source acceptable if security can be verified; dependency vulnerability scanning required; active maintenance and community support verified; licensing compatibility assessed; commercial support available (preferred for critical components); security response process for vulnerabilities documented.
14. Vendor Risk Register
14.1 Risk Register Maintenance
Comprehensive risk register documenting: vendor name and service; risk classification (Low, Medium, High, Critical); specific risks identified (security, operational, financial, compliance); likelihood and impact assessment; mitigating controls implemented; residual risk level; risk owner within Company; risk treatment plan; review date.
14.2 Risk Escalation
Risk escalation triggers: vendor security incident or breach; vendor financial difficulty or instability; loss of required certifications; significant service degradation; contract disputes or non-compliance; regulatory concerns; change in vendor ownership or service.
Escalation Process: Risk owner notifies CTO immediately; enhanced monitoring implemented; risk treatment plan updated; more frequent reviews scheduled; alternative vendor evaluation initiated if necessary; senior management notified for critical vendors.
15. Compliance And Audit
15.1 Vendor Compliance Requirements
GDPR Compliance: All vendors processing personal data must comply with GDPR; Data Processing Agreements in place; data subject rights support procedures defined; breach notification procedures established; international data transfer mechanisms compliant.
Industry Standards: ISO 27001 compliance preferred for critical vendors; SOC 2 Type II reports for critical vendors; industry-specific certifications (PCI DSS, HIPAA) as applicable.
15.2 Vendor Audits
Audit Schedule: Critical vendors: annual audits; High-risk vendors: bi-annual audits or upon contract renewal; Medium-risk vendors: audit upon contract renewal; Triggered audits: following incidents or significant changes.
Audit Types: Documentation Review; Questionnaire (comprehensive security and privacy questionnaires); Third-Party Reports (review SOC 2, ISO 27001 audit reports); On-Site Audit (physical inspection for critical vendors); Technical Audit (penetration testing, vulnerability assessment for critical vendors).
Audit Documentation: Audit plan and scope; audit findings and observations; vendor responses and remediation plans; follow-up actions and timelines; audit completion sign-off.
15.3 Regulatory Audits
Supporting Customer/Regulatory Audits: Vendor documentation available for regulatory audits; vendor audit rights exercised to obtain compliance evidence; vendor security and compliance reports provided to auditors; coordinate with vendors during customer audits; maintain audit trail of vendor management activities.
16. Roles And Responsibilities
| Role | Responsibilities |
|---|---|
| CTO (Responsible Person) | Overall vendor management policy ownership; approve Medium/High/Critical vendor engagements; conduct vendor security assessments; manage critical vendor relationships; vendor incident response; review vendor register quarterly; escalation point for vendor issues |
| Department Managers | Identify vendor needs; conduct business requirements assessment; approve Low-risk vendors; manage vendor day-to-day relationships; monitor vendor performance; report vendor issues; ensure contract compliance |
| Finance/Procurement | Contract negotiation and execution; invoice processing; payment management; contract renewal tracking; cost optimization; financial risk assessment |
| Legal (External Counsel) | Contract review and negotiation; Data Processing Agreement review; legal compliance advice; dispute resolution; regulatory liaison if needed |
| Product Manager | Vendor technical requirements; vendor integration oversight; vendor performance feedback; feature and functionality assessment |
| All Employees | Report vendor security concerns; comply with vendor usage policies; protect vendor credentials; follow data sharing procedures; report vendor performance issues |
17. Training And Awareness
17.1 Vendor Management Training
Required Training:
- Managers: Vendor assessment and selection procedures
- Technical staff: Vendor security assessment, integration security
- All staff: Acceptable use of vendor services, data protection with vendors
Training Topics: Vendor risk classification; security assessment procedures; contract and DPA requirements; ongoing vendor monitoring; incident reporting for vendor issues; data protection when working with vendors.
17.2 Vendor Resources
Available Resources: Vendor assessment checklist and templates; standard Data Processing Agreement template; security questionnaire templates; contract security requirements checklist; vendor incident reporting procedures; vendor register and documentation repository.
18. Exceptions
18.1 Exception Process
Exceptions to vendor management requirements may be requested for: emergency situations requiring immediate vendor engagement; unique vendor services with no alternatives; cost constraints requiring compromise on requirements; technical limitations of available vendors.
All exceptions must:
- Be requested in writing to CTO with detailed justification
- Document compensating controls to mitigate risks
- Be approved in writing by CTO (and CEO for critical vendors)
- Be time-limited and reviewed quarterly
- Be documented in vendor register with risk assessment
18.2 Legacy Vendors
Vendors engaged before this policy implementation: retrospective assessment conducted within 12 months; bring into compliance with policy requirements; update contracts and DPAs to meet requirements; terminate if cannot meet minimum requirements.
19. Policy Review And Updates
19.1 Review Schedule
This policy will be reviewed:
- Annually: Comprehensive review by CTO
- After vendor incidents: Update based on lessons learned
- Regulatory changes: Updates for GDPR or other regulatory changes
- Significant vendor changes: Major vendor acquisitions, service changes
- After audits: Update based on audit findings
19.2 Continuous Improvement
- Monitor vendor management best practices
- Incorporate lessons learned from vendor incidents
- Update vendor assessment criteria based on evolving threats
- Enhance monitoring and automation
- Streamline processes for efficiency
20. Related Policies
This policy should be read in conjunction with:
- Information Security Policy
- Data Protection Policy
- Cloud Security Policy
- Encryption Policy
- Access Management Process/Procedure
- Incident Response Plan
- Change Control Policy
- Procurement Policy (if applicable)
21. Contact Information
For questions regarding this policy or to report vendor security incidents:
Data Protection Officer / CTO: Andrés Pitt Email: andres@vstream.ie Phone: (086) 788 6570