The company formally assesses the security posture of suppliers and vendors before engaging with them
Requiring a documented security check of every new supplier before the contract is signed supports A.5.19's due diligence requirement, though it does not cover the ongoing supplier risk management the control also demands.
Documented security checks before a contract is signed extend A.5.21's supply chain risk management to the point a new dependency is first introduced.
This Sekit policy requires a documented security check of a new supplier before the contract is signed, exactly the oversight A.8.30 requires when development work is outsourced.
https://sekit.ai/api/mcp/crosswalk