ED Decision 2023/009/R
The purpose of the prior assessment is to evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the information security activities to be contracted. This prior assessment may need to be carried out taking into account other legal requirements or procurement procedures that apply to the organisation, and may therefore be carried out in different ways, such as:
(a) in case of public bids, inclusion of eligibility requirements in the procurement documents for the potential suppliers;
(b) review of the information security certifications granted by external and impartial auditors to the potential suppliers;
(c) review of self-assessment questionnaires compiled by the potential suppliers;
RISK ASSESSMENT ASSOCIATED WITH THE PROVISION OF THE CONTRACTED ACTIVITIES
The risk assessment should take into account the maturity level of the contracted organisation, and should consider the following:
(a) identification and assessment of critical and sensitive information and assets that may be shared with, or provided by, external suppliers;
(b) identification of the information security requirements of the organisation that are applicable to the contracted organisation;
(c) evaluation, by means of a supplier assessment, of the ability of the contracted organisation (both existing and new contracted organisations) to meet the information security requirements of the contracting organisation;
(d) assessment of risks that may be introduced by the contracted organisation.
This agreed risk assessment should also consider the roles and responsibilities of the contracting and contracted organisation as well as their interfaces.
Guidance on prior assessment of suppliers' competencies and risk assessment for contracted information security activities, including supplier evaluation and roles.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...