Vendors:
- Do you inspect the tools that are brought into your enterprise to manage information systems as part of a contract?
- Contract SLAs will not prevent your organization from receiving malware from infected vendor devices
- Do you monitor third-party connections from vendors?
- These connections can serve as a conduit for data exfiltration or malware infections
Subcontractors/partners:
- Are your subcontractors required to follow the same information security requirements as you?
- This can pose a serious concern to any contracts that you may have where compliance is a key performance requirement
- Do subcontractors use their own equipment or yours in commissions of contract activities?
Subsidiaries/divisions: ...