Technology & Digital

Vendor Information Security Addendum

Security addendum to a vendor or supplier contract. Covers access control, encryption, subprocessors, vulnerability management, breach notification windows, audit and certification evidence, and data return or destruction on exit. Two signers (customer and vendor).

📄 2 signers📅 30-day expiry🏷 Technology & Digital🔖 two-signers, addendum, security, vendor, compliance

About this template

The Vendor Information Security Addendum is a ready-to-use technology & digital template you can send for signature in minutes. It is written for 2 signers (customer and vendor) and, by default, expires 30 days after it is sent if left unsigned. It covers two signers, addendum, security, vendor, compliance. Like every Abundera Sign template it is a convenience draft structured for ESIGN Act and UETA compliance, not a substitute for legal advice. Each signed copy is sealed with PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package in WORM storage.

Document Preview

# Vendor Information Security Addendum **Effective Date:** ___________ This Information Security Addendum ("Addendum") supplements and forms part of the agreement identified below (the "Underlying Agreement") between: **Customer:** ___________ ("Customer") **Vendor:** ___________ ("Vendor") **Underlying Agreement (title and date):** ___________ Where this Addendum conflicts with the Underlying Agreement on a security matter, this Addendum controls. ## 1. Scope of Data and Systems **Customer data Vendor will handle:** ___________ **Vendor access model:** ___________ **Approximate record volume:** ___________ ## 2. Baseline Security Controls Vendor shall maintain an information security programme appropriate to the sensitivity of the data, and shall at minimum: - Encrypt Customer data in transit using current, non-deprecated protocols. - Encrypt Customer data at rest. - Enforce unique named accounts, with no shared or generic credentials for administrative access. - Require multi-factor authentication for all administrative and remote access. - Apply least-privilege access, reviewed at least annually and revoked within one business day of a role change or departure. - Maintain audit logs sufficient to reconstruct access to Customer data, retained for the period stated below. - Separate production from development and test environments, and not use live Customer data in non-production environments without written approval. **Audit log retention:** ___________ ## 3. Personnel Vendor shall carry out background screening on personnel with access to Customer data, to the extent permitted by law, and shall require those personnel to be bound by written confidentiality obligations that survive their engagement.

Fields (33)

effective date
date · required
customer name
text · required
vendor name
text · required
underlying agreement
text · required
data categories
select · required
access model
select · required
record volume
select · required
log retention
select · required
training frequency
select · required
remediation critical
select · required
remediation high
select · required
pentest frequency
select · required
uses subprocessors
radio · required
subprocessor list
textarea · required
subprocessor notice
select · required
breach notice hours
select · required
vendor security email
email · required
customer security email
email · required
rto
select · required
rpo
select · required
backup test frequency
select · required
certifications
select · required
audit right
select · required
deletion deadline
select · required
destruction certificate
radio · required
permitted secondary use
textarea
data locations
textarea · required
additional terms
textarea
governing law
text
customer signer name
text · required
customer signer title
text · required
vendor signer name
text · required
vendor signer title
text · required

Related Technology & Digital templates

All 40 Technology & Digital templates →  ·  Browse all templates →

Send this template with cryptographic proof

Every signed document gets PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package sealed in WORM storage.

Try the DemoView PricingFounding Member — 50% Off