Back to all articles

Business System, Asset and Third-Party Assessment Template (Overview)

The Business System, Asset and Third-Party Assessment Template is designed to be completed when new software vendors (Third Parties) are being onboarded within the organisation.

The assessment can be completed before the Third Party/software is procured to ensure that security and privacy risks are reviewed and addressed at this stage. Third Party, and related Business Systems & Asset status, can be set as planned. Optional controls/evidence can be added for the Assets and Third Party at this stage if required.

The assessment is designed to be completed internally by the Information Security or Data Protection departments; however, if required, it can be targeted to the relevant department procuring the software, or externally for Third Parties for completion.

Once the assessment has been completed, the Business System, Third Party and Asset(s) will populate into the relevant registers, and the records will be linked together. The Program/Assessment Reviewer will also receive a notification to review and approve the assessment.

Note: This base template is available for use ‘out of the box’; however, you do have the option of customising the assessment questioning, updating guidance, and with adding any extra questions to ensure all of your organisational requirements are met.

Please see below an overview of the 3 registers that are used in this assessment.

mceclip0.png