Wikier

Information security

Vendor information security - policy

Policy for Vendor Information Security

Norwegian version - Retningslinje for informasjonssikkerhet i leverandørforhold

  • Document type: Topic specific policy
  • Managed by: CISO, Digital Security Section
  • Approved by: Director of Organization and infrastructure
  • Valid from: 01.10.2025
  • Next revision within: 01.10.2027
  • Classification: Open
  • Reference ISO: ISO27002:2022 5.10,5.19,5.20
  • Reference Policy on information security and data protection in higher education and research (F-04-20): Pt 5
  • Reference NSMs principles for ICT security: 1.3.3c, 2.1.4
  • Reference Law/Rule: eGovernment Regulations (eForvaltningsforskriften)
  • Reference internal documents: Superior Information Security Policy, NTNUs Governance document for Security and Emergency Preparedness

Purpose

The purpose of this policy is to ensure that NTNU’s vendors:

a. Are familiar with NTNU’s procedures for vendor follow-up

b. Safeguard NTNU’s information assets in accordance with requirements for confidentiality, integrity, and availability

c. Process personal data about students, employees, research participants, and others in accordance with applicable laws

The guideline shall also ensure that NTNU follows up on its vendors in a responsible manner. The guideline covers ICT systems, ICT platforms, software, and applications.

Applies to

a. Anyone responsible for vendor follow-up or vendor management at NTNU

b. Anyone with procurement needs at NTNU, including purchasers of the following types of ICT tools:

  • IT systems, services, and components handling information requiring security measures against unauthorized access (includes systems with internal, confidential, and highly confidential data, and systems that should be protected for other reasons)
  • Cloud services and external storage solutions with risk of data transfer outside the EEA
  • Research tools and applications that may contain confidential information and require extra security measures (especially strict requirements apply if special categories of personal data are involved)
  • Systems handling personal data – e.g., CRM systems, HR tools, research databases requiring data processing agreements and access control (especially strict requirements apply if special categories of personal data are involved)

Responsibilities and Roles

Information security work affects all levels of the organization. Responsibility and authority follow the regular line responsibility, as defined in the Information Security Policy

For this policy, the Head of the Finance Department, system owner, and system administrator have central roles and responsibilities

General Principles

a. All vendors must comply with NTNU’s information security requirements according to the “Information Security Policy”

b. Vendors must accept a data processing agreement

c. Vendors must receive adequate training in NTNU’s security requirements before accessing NTNU’s ICT systems

d. All vendors must comply with the GDPR and NTNU’s guidelines for processing personal data

Documentation and Management Requirements

Documentation Requirements

NTNU must maintain an overview of vendors. A vendor list must include:

a. Vendor name

b. Vendor contact for contract execution

c. NTNU contact for contract execution

d. Contract duration

e. Link to the agreement, including any amendments

f. Overview of delivery areas covered by the agreement

g. vendor access to NTNU’s ICT infrastructure and/or information assets

h. Classification level of information the vendor has access to

i. Whether the vendor processes personal data on behalf of NTNU, and if a written data processing agreement exists (with link)

j. Whether the vendor’s services are critical for NTNU’s ICT infrastructure operation

k. Whether a risk assessment and possibly a DPIA has been conducted if personal data is transferred to or accessed by the vendor during the contract period

l. Overview of technical and organizational measures implemented to ensure information and personal data security

Vendor Management

When contracting external service providers for digital systems or services, NTNU is responsible for ensuring adequate information security. This responsibility applies throughout the vendor chain.

NTNU must manage vendor agreements responsibly, which includes:

a. Having routines for vendor agreement management. Deliveries must be regularly evaluated and audited to ensure compliance with information security and privacy requirements

b. Including information security and privacy requirements in specifications from the planning phase and throughout the ICT tool’s lifecycle

c. Departments must maintain an updated list of all vendors in the case and archive system Elements

d. External parties must sign an access agreement before being granted physical or logical access to ICT infrastructure

e. When transferring personal data abroad, NTNU must ensure security and compliance with GDPR, including risk assessments and use of EU standard contracts

f. Data processors may use subcontractors, but NTNU must approve them

Agreements with Vendors

When NTNU uses service providers and data processors, NTNU holds the legal responsibility for data processing. NTNU’s guidelines for personal data processing also apply to vendor relationships.

As data controller, NTNU must ensure that the data processor provides sufficient guarantees, technical and organizational measures to meet the regulation’s requirements and protect data subjects’ rights.

Vendor agreements must include:

a. Distribution of roles and responsibilities in contract management: It must be clear who is responsible for various aspects of contract management to ensure effective follow-up and handling of agreements

b. Overview of NTNU’s processing activities

c. Information flow between the roles: Description of how information should flow between the different roles to ensure that all relevant parties [have access to] the information flow between the parties.

d. Control points to verify that confidentiality, integrity, and availability (CIA) requirements are met

e. Cooperation in case of serious incidents or crises: Description of how NTNU and the vendor must cooperate in the event of a serious incident or crisis to ensure swift and effective response

f. Termination procedures: Upon termination of the agreement, all information and assets must be returned or deleted to protect NTNU's data and assets.

g. Training and awareness: Vendors shall receive regular training on NTNU's security requirements and data protection policies to ensure the secure handling of information.

h. Privacy: Requirements for processing personal data, including how vendors must handle personal data in accordance with GDPR and other relevant laws to ensure compliance with applicable legislation and NTNU's policies.

i. Incident reporting: Description of procedures on how vendors should report to and notify NTNU in case of deviations

j. Auditing and supervision: Requirements for audits and supervision to ensure vendor compliance with security requirements. This includes conducting internal and external audits and addressing audit findings through technical and organizational measures