Security addendum to a vendor or supplier contract. Covers access control, encryption, subprocessors, vulnerability management, breach notification windows, audit and certification evidence, and data return or destruction on exit. Two signers (customer and vendor).
The Vendor Information Security Addendum is a ready-to-use technology & digital template you can send for signature in minutes. It is written for 2 signers (customer and vendor) and, by default, expires 30 days after it is sent if left unsigned. It covers two signers, addendum, security, vendor, compliance. Like every Abundera Sign template it is a convenience draft structured for ESIGN Act and UETA compliance, not a substitute for legal advice. Each signed copy is sealed with PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package in WORM storage.
Document Preview
# Vendor Information Security Addendum **Effective Date:** ___________ This Information Security Addendum ("Addendum") supplements and forms part of the agreement identified below (the "Underlying Agreement") between: **Customer:** ___________ ("Customer") **Vendor:** ___________ ("Vendor") **Underlying Agreement (title and date):** ___________ Where this Addendum conflicts with the Underlying Agreement on a security matter, this Addendum controls. ## 1. Scope of Data and Systems **Customer data Vendor will handle:** ___________ **Vendor access model:** ___________ **Approximate record volume:** ___________ ## 2. Baseline Security Controls Vendor shall maintain an information security programme appropriate to the sensitivity of the data, and shall at minimum: - Encrypt Customer data in transit using current, non-deprecated protocols. - Encrypt Customer data at rest. - Enforce unique named accounts, with no shared or generic credentials for administrative access. - Require multi-factor authentication for all administrative and remote access. - Apply least-privilege access, reviewed at least annually and revoked within one business day of a role change or departure. - Maintain audit logs sufficient to reconstruct access to Customer data, retained for the period stated below. - Separate production from development and test environments, and not use live Customer data in non-production environments without written approval. **Audit log retention:** ___________ ## 3. Personnel Vendor shall carry out background screening on personnel with access to Customer data, to the extent permitted by law, and shall require those personnel to be bound by written confidentiality obligations that survive their engagement.