Frequently Asked Question
Supplier Risk Assessment Policy
Last Updated a year ago
Purpose
This policy establishes guidelines for assessing the cybersecurity risks associated with new suppliers and vendors to protect Chroma Colors Corporation's sensitive information and systems.
Scope
This policy applies to all new suppliers and vendors who have access to Chroma Colors Corporation's systems, data, or information.
Responsibilities:
- Procurement:
Identify and evaluate potential suppliers based on cybersecurity risk factors. - Information Security: Conduct cybersecurity risk assessments for new suppliers and vendors.
- Supplier Management: Manage supplier relationships.
Risk Assessment Process:
- Supplier Identification: Identify all new suppliers and vendors who will have access to Chroma Colors Corporation's systems or data.
- Risk Assessment: Conduct a thorough cybersecurity risk assessment using the Chroma Supplier Risk assessment based on the NIST Cybersecurity Framework.
- Assessment Validation – Request three artifacts in support of completed risk questionnaire.
- Risk Evaluation: Evaluate the identified risks based on their likelihood and potential impact on Chroma Colors Corporation. Submissions should be sent in to the Security and Operations Helpdesk at [email protected]
- Risk Mitigation: Develop and implement appropriate risk mitigation measures to address the identified risks.
- Documentation:
Document the risk assessment process, findings, and mitigation measures
Policy Enforcement:
- Non-Compliance:
Failure to comply with this policy may result in the termination of the supplier relationship. - Regular Reviews: This policy will be reviewed annually to ensure its effectiveness and alignment with evolving cybersecurity threats and best practices
By following this policy, Chroma Colors Corporation can effectively manage cybersecurity risks associated with new suppliers and vendors, protecting its sensitive information and systems