Register of third parties #
Lens and screen #
The Third Parties menu centralizes name, contact, services, criticality, responsible, entrusted data, dependencies, contract/SLA, deadlines, exit plan and cyberscore.
Manage a third party #
Create the form, document criticality and dependencies, then maintain contract and release. Modification or deletion is refused if the object belongs to another tenant; check the relationships before archiving.
Supplier campaign #
Launch an evaluation: the version and weightings of the questionnaire are fixed. The provider responds via an expiring opaque token, without access to the tenant. An internal review is mandatory before updating the cyberscore.
Best practices #
Scale frequency to criticality, require proof benchmarks, and test the release plan for strong dependencies.
Prerequisites and responsibilities #
Designate an active internal owner. Gather available contract, SLA, services, data categories, dependencies and certifications. The file belongs to the tenant and must not serve as a free portal for the supplier.
Description of the file #
| Field | Use |
|---|---|
| Name / contact | identity and coordination point |
| Services | services actually consumed |
| Criticality | low, medium, high or critical |
| Status | prospect, active, suspended, planned exit or completed |
| Data | entrusted or accessible categories |
| Contract / SLA | references and commitments |
| Dependencies | related processes, assets and suppliers |
| End of contract | anticipation of renewal or exit |
| Next review | review deadline |
| Exit plan | reversibility, data, access and continuity |
| Cyberscore | consolidated result after review |
Create and qualify a third party #
- Search for an existing third party to avoid duplicates.
- Enter identity, contact, services and owner.
- Classify criticality according to dependency, data and impact.
- Document contract, SLA, certifications and deadlines.
- Add risk summary and compensatory measures.
- Set the next evaluation.
- Write an exit plan proportionate to criticality.
Life cycle #
A Prospect can become Active after contracting. Suspended indicates a temporary interruption. Planned exit prepares for reversibility. Done keeps history. Before changing state, check incidents, dependencies, access and data to be restored or deleted.
Launch a supplier campaign #
The campaign freezes title, version of the questionnaire, questions and weightings. Choose an internal reviewer and an expiration, then send the opaque link to the authorized contact.
The supplier only sees his questionnaire. He enters the answers and evidence references, then submits. The statuses are Draft, Sent, In Progress, Submitted, Reviewed or Expired.
Internal review and cyberscore #
The reviewer checks consistency, evidence and critical responses before validation. The questionnaire score only updates the third party's cyberscore after this review. Document reservations and compensatory measures; do not confuse high score with lack of risk.
Portal security #
The public token has 256 bits of randomness and one expiration. It does not open any private API of the tenant. After exposure or sending to the wrong recipient, let it expire or recreate the campaign depending on the available functions.
Filters, deadlines and controlsPrioritize critical third parties, contracts close to expiry and late evaluations. Before annual review, check ownership, services, data, SLAs, dependencies, incidents, certifications, cyberscore and exit plan. #
Common errors #
An invisible reviewer can be inactive or offline. An expired campaign no longer accepts responses. Do not copy sensitive evidence in an open field: use controlled references.
Example #
A host handling backups is classified critical. The file documents location, encryption, SLA, dependency, certification, deadline and restitution/destruction procedure. The annual campaign conditions the maintenance of compensatory measures.