Supplier inventory and criticality
The list comes first: which supplier reaches which data, which system, with which privileges. Criticality follows the class of data reached and the business impact of an outage — not the size of the supplier.
- Subcontractors belong in the inventory too
- Criticality is set by data class and business impact
- A supplier whose access ends leaves the inventory
- The inventory is wired into the procurement process
Contract and obligations
A contract is where the arguments that would follow an incident are settled in advance: breach notification timing, audit rights, use of subcontractors, what happens to data at the end. Under Turkish data protection law a processor agreement is separately required.
- Breach notification timing is written as a number
- Use of subcontractors requires permission
- Return and destruction of data at contract end is defined
- Audit rights are drafted so they can actually be exercised
Access design
The most effective control is that a supplier cannot reach anything it does not need. Access is opened for a task and expires, sessions are recorded, and no standing privileged account is issued.
- Access opens on a work request and closes on expiry
- Session records allow the work to be reviewed later
- No standing privileged accounts are issued
- Network reach is limited to the required destinations
Awareness and behavior
Awareness training is measured by behavior change, not by attendance. Simulation results, reporting rates and repeated mistakes are tracked together; the aim is less risky behavior, not punishment.
- The measure is reporting and error rate, not attendance
- Simulation difficulty increases in stages
- Results are reported at group level, not per person
- A repeated mistake signals a process problem, not a training gap