Why this module exists. The threat model has shifted. The hardest perimeter to defend now is your vendors’ perimeter. This module is the practitioner programme: how to tier, assess, monitor, and respond.
The tiering — start here
Not every vendor needs the same scrutiny. Categorise based on data sensitivity, access level, and operational dependency:
| Tier | Examples | Assessment depth |
|---|---|---|
| Tier 1 — Critical | Cloud (AWS, Azure), Payment processor, KMS provider, Core banking platform | SOC 2 Type II + on-site / virtual audit annually + contractual right to audit |
| Tier 2 — High | HR platform with PII access, identity provider, MDM, SIEM | SOC 2 Type II review + questionnaire + reference checks |
| Tier 3 — Medium | Marketing automation, analytics, CRM | Self-attestation questionnaire + public security posture review |
| Tier 4 — Low | Office supplies, travel booking, generic SaaS | Standard procurement clauses only |
The questionnaire problem
Most Indian-enterprise vendor questionnaires are 200+ questions of compliance theatre. Vendors copy-paste answers from the last one. The information value is near zero.
The right approach: SIG (Standardised Information Gathering) or CAIQ (Consensus Assessments Initiative Questionnaire) as the standard format. Vendors who have completed these for other customers can share once. You combine with evidence collection:
- Most recent SOC 2 Type II report (the report, not just the certificate).
- Most recent independent penetration test summary.
- Most recent ISO 27001 surveillance audit report.
- Breach disclosure history — anything in the last 24 months.
- Subprocessor list and the certifications they hold.
The questionnaire answers fill in the gaps the documents do not cover. The documents are evidence; the questionnaire is interpretation.
The contract — clauses that matter
- Breach notification timeline. 24 hours of vendor’s becoming aware. Tighter than DPDP 72h to give you headroom for your own regulatory clock.
- Right to audit. Especially for Tier 1. Quarterly virtual; annual on-site.
- Subprocessor consent. Vendor must notify before adding a new subprocessor; you retain right to object.
- Data location and residency. Where your data is stored, with notification before any change. DPDP Phase 2 makes this auditable.
- Data deletion / return on termination. Verifiable proof of deletion, not just an attestation.
- Liability cap. Sufficient relative to the data sensitivity. ₹2 Cr cap on a vendor processing 4M customer records is insufficient.
- Cyber-insurance evidence. Vendor provides annual proof of cyber coverage at appropriate limits.
Continuous monitoring — what to watch after onboarding
- BitSight / SecurityScorecard / RiskRecon: external attack-surface ratings. Useful for Tier 1-2; cost £/$ scales fast.
- Have I Been Pwned domain monitoring: alert when employees of a critical vendor appear in breach corpora.
- Public-facing CVE feed: subscribe to vendor’s security advisory channel. RSS, email, security.txt.
- SOC integration: critical vendors should provide a security data feed or, at minimum, periodic threat-intel briefings.
- Annual reassessment: re-run the questionnaire and evidence collection annually for Tier 1-2; biennial for Tier 3.
Supply-chain attack scenarios — what to specifically defend against
- Compromised software update (SolarWinds pattern). Defender: code-signing verification on updates; staged rollout with monitoring before fleet-wide.
- Compromised dependency (Log4j, XZ pattern). Defender: SBOM tracking, dependency-pinning, scanning for known-vulnerable transitives.
- Compromised SaaS vendor (Okta pattern). Defender: tier-1 vendor controls; minimise blast radius via least-privilege OAuth scopes.
- Compromised hardware (TigerJet, rare but exists). Defender: source from supply-chain-attested vendors for sensitive deployments.
The Indian-regulatory overlay
- DPDP Rules: data processor contracts mandatory; data fiduciary remains responsible for processor breaches.
- RBI Cyber Security Framework: explicit third-party risk management requirements; ESC vendor due diligence is regulator-inspected.
- RBI IT Outsourcing Master Direction: prescribes a 12-element due-diligence process for IT outsourcing vendors; mandatory exit plan for critical services.
- SEBI CSCRF: third-party security as a named control domain.
Onboarding — the rapid-assessment pattern
Procurement teams want vendor onboarding in weeks, not months. The pattern that works:
- Tier the vendor in week 1 based on data + access + criticality.
- Tier 4: standard procurement clauses; no further security review.
- Tier 3: 30-question self-attestation completed by vendor; security review <2 days.
- Tier 2: SOC 2 Type II review + condensed questionnaire; 1-2 weeks.
- Tier 1: full assessment; 3-6 weeks; security veto if findings unacceptable.
Make the timeline visible to procurement so they plan accordingly.
Key takeaways
- Tier vendors 1-4 by data sensitivity, access level, operational dependency.
- Evidence first (SOC 2, pentest, breach history); questionnaire fills gaps.
- Contract clauses: notification, right to audit, subprocessor consent, residency, deletion, liability cap, insurance.
- Continuous monitoring: external rating service for Tier 1-2; annual reassessment.
- Defend against four supply-chain attack patterns: software update, dependency, SaaS, hardware.
- India regulatory: DPDP processor contracts, RBI IT Outsourcing, SEBI CSCRF.
Get a DPDP gap assessment
Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.