Table of Contents
- 1. Purpose
- 2. Scope
- 3. Policy Statement
- 4. Roles and Responsibilities
- 5. Policy Requirements
- 6. Implementation Guidance
- 7. Monitoring, Evidence, and Compliance
- 8. Exceptions
- 9. Review and Maintenance
- 10. Related Standards
1. Purpose
This policy establishes a structured, risk-based approach for selecting, contracting, onboarding, monitoring, and offboarding vendors and third parties that may access Ligala Tech Pte systems, data, or services. Ligala Tech Pte operates in legal technology, where the confidentiality, integrity, and availability of client information are critical, and where third-party failure can create direct legal, regulatory, and reputational harm. Because the company is small, with limited staffing and high reliance on external services, vendor governance must be practical, repeatable, and tightly aligned to business risk.
This policy is intended to protect personal data and sensitive legal information in accordance with Singapore Personal Data Protection Act (PDPA) obligations and information security requirements aligned to ISO 27001. It addresses risks arising from cloud service providers, software vendors, contractors, outsourced support, and other third parties that may process, store, transmit, administer, or otherwise interact with Ligala Tech Pte information assets. It is especially important in light of the open finding involving the overly permissive AWS SSO administrator role, which demonstrates the need to tightly restrict privileged access and verify that third-party access is granted only for approved business purposes.
The policy also supports operational resilience by requiring documented due diligence, defined accountability, ongoing monitoring, and timely offboarding. By applying consistent controls to external relationships, Ligala Tech Pte reduces the likelihood of unauthorized access, data misuse, service disruption, and inadequate incident response. The policy is designed to be practical for a small organization while still meeting a mature security and privacy governance standard.
2. Scope
This policy applies to all vendors, suppliers, contractors, consultants, managed service providers, cloud service providers, resellers, freelancers, and other third parties that access, process, store, transmit, support, or administer Ligala Tech Pte systems, services, or data. It includes both direct relationships and subprocessor or subcontractor relationships where third parties are used by a primary vendor to deliver services to Ligala Tech Pte. The policy covers production, development, testing, and administrative environments whenever company information or access credentials are involved.
The policy applies to all forms of third-party access, including logical access, API access, remote support access, privileged administrative access, account creation, data exports, and integration tokens. It also applies to vendors that may not have direct system access but may receive personal data, client records, security logs, legal documents, or other confidential information in the course of service delivery. Where a vendor handles data on behalf of Ligala Tech Pte, the vendor must be treated as a security and privacy risk subject to review before engagement and throughout the relationship.
This policy applies to all employees, officers, founders, and authorized representatives who initiate, approve, manage, or terminate vendor relationships. Because Ligala Tech Pte is a small company, the same person may perform multiple roles in practice, but required control steps and approvals must still be completed and documented. No vendor may bypass this policy because of urgency, existing relationships, budget constraints, or perceived low risk.
3. Policy Statement
Ligala Tech Pte shall only engage third parties after completing risk-based due diligence proportional to the sensitivity of the information involved, the access required, the criticality of the service, and the legal and operational impact of failure. Every third-party relationship must have a legitimate business purpose, a defined owner inside Ligala Tech Pte, documented contractual terms, and appropriate security and privacy controls before access is granted. Vendors that handle personal data, confidential client information, production systems, or privileged administrative functions require enhanced review and explicit approval.
Access granted to third parties must follow least privilege, time-bound authorization, and strong authentication. Privileged access, especially to cloud environments, must be tightly controlled, monitored, and removed when no longer required. The open finding related to the AWS administrator role underscores that broad administrative permissions are not acceptable for third-party use unless formally justified, approved, and implemented with compensating controls. Shared accounts are prohibited, and all access must be attributable to an individual or a controlled service identity.
Third-party obligations must be contractually binding and must address confidentiality, data protection, subprocessing, security incident notification, audit rights where appropriate, service continuity, and secure data return or deletion at offboarding. Vendors must be monitored throughout the relationship, not only at onboarding, with reassessment triggered by major changes in service scope, security posture, ownership, data location, or incident history. When a vendor no longer meets expectations or the business need ends, access and data sharing must be terminated promptly and verified.
4. Roles and Responsibilities
- Managing Director / Executive Approver: Approves high-risk vendor engagements, material exceptions, and continued use of vendors that process sensitive legal or personal data when residual risk exceeds routine thresholds.
- Security Lead / Information Security Owner: Defines minimum security requirements, reviews technical controls, assesses privileged access, monitors cloud and system exposure, and validates evidence for security-related requirements.
- Privacy / Data Protection Lead: Reviews personal data handling, cross-border transfers, retention, deletion obligations, and vendor privacy commitments under PDPA-related requirements.
- Procurement or Vendor Owner: Maintains the vendor register, coordinates due diligence, ensures contracts include required clauses, tracks renewal dates, and confirms offboarding actions are completed.
- Business Service Owner: Defines the business need, data types, access scope, and criticality of the service; validates that the vendor remains necessary and that performance continues to meet business expectations.
- IT / Cloud Administrator: Implements technical controls such as access provisioning, MFA, role restrictions, logging, token management, and access removal for vendor accounts and integrations.
- Legal or External Counsel Liaison: Reviews contractual language for confidentiality, liability, data processing, cross-border transfer, and dispute or termination provisions when required by deal complexity or risk.
- Vendor Contact / Account Manager: Provides security and compliance evidence, notifies Ligala Tech Pte of incidents or changes, supports remediation, and confirms deletion or return of data at contract end.
5. Policy Requirements
- All vendors must undergo risk-tiering before contract signature; the Procurement or Vendor Owner owns this; it occurs for every new engagement and at renewal; evidence includes a completed vendor risk assessment and documented risk tier.
- Vendors that process personal data must have a documented data protection review; the Privacy / Data Protection Lead owns this; it occurs before onboarding and after material change; evidence includes a completed privacy checklist or DPIA-style review where warranted.
- Vendors with system access must complete security due diligence covering authentication, logging, vulnerability management, and incident response; the Security Lead owns this; it occurs before access approval and annually for high-risk vendors; evidence includes completed security questionnaire and reviewed supporting artifacts.
- All third-party access must be approved by the Business Service Owner and implemented by IT with least privilege and MFA; ownership is shared between the Business Service Owner and IT / Cloud Administrator; it occurs before access is issued and whenever scope changes; evidence includes approval record, access request, and IAM configuration.
- Privileged access for vendors is prohibited unless explicitly justified and time-bound; the Security Lead owns the control; it occurs for every privileged request and is reviewed at least monthly; evidence includes approved privileged access request, expiration date, and logs showing scope limitations.
- Vendor contracts must include confidentiality, data processing, breach notification, subprocessor controls, deletion/return, and termination assistance clauses; Legal or Procurement owns this; it occurs before signature and at renewal; evidence includes executed agreement and clause review checklist.
- Vendors may not use sub-processors for Ligala Tech Pte data without written notification and approval where required; the Privacy / Data Protection Lead owns review and the Procurement or Vendor Owner records approval; it occurs before initial subcontracting and upon change; evidence includes subprocessor disclosure and approval record.
- Security incidents affecting Ligala Tech Pte data or systems must be reported by the vendor within the contractually defined timeframe, with an internal escalation path established; the Vendor Owner owns escalation and Security Lead coordinates response; it occurs for every incident; evidence includes incident notice, case log, and post-incident review.
- Vendor access must be reviewed on a scheduled basis and removed when no longer required; IT / Cloud Administrator owns implementation and Business Service Owner validates necessity; it occurs at least quarterly for vendors with access and immediately upon offboarding; evidence includes access review report and deprovisioning ticket.
- Vendor performance, security posture, and compliance status must be monitored against agreed obligations; the Vendor Owner owns monitoring and the Security Lead supports high-risk reviews; it occurs quarterly for high-risk vendors and annually for lower-risk vendors; evidence includes scorecards, review notes, and remediation actions.
- Data retention, return, and secure deletion obligations must be defined and verified at offboarding; the Procurement or Vendor Owner owns coordination and the Privacy / Data Protection Lead confirms data handling expectations; it occurs at contract end or termination; evidence includes deletion certificate, return confirmation, and access revocation records.
- Any material vendor issue, including repeated control failures, unresolved audit findings, or critical availability problems, must trigger escalation to the Managing Director; the Vendor Owner initiates escalation; it occurs when threshold events are observed; evidence includes escalation memo, remediation plan, and management decision.
- Vendors that support production or legal-sensitive workloads must maintain business continuity arrangements proportionate to service criticality; the Business Service Owner owns continuity requirements and Procurement ensures contractual inclusion; it occurs before go-live and is reviewed annually; evidence includes continuity provisions, recovery commitments, or tested backup/restore evidence where applicable.
6. Implementation Guidance
Ligala Tech Pte should implement this policy using a simple but disciplined vendor lifecycle. The first step is intake: every proposed vendor should be logged in a vendor register with the service description, data involved, access type, location of processing, business owner, and renewal date. The Vendor Owner should assign a preliminary risk tier based on whether the vendor touches personal data, production systems, privileged access, or regulated legal content. Low-risk services such as office tools may receive lighter review, while cloud, support, and data-processing vendors must receive deeper scrutiny.
During due diligence, the Security Lead should request evidence appropriate to risk, such as SOC 2 reports, ISO 27001 certification, penetration test summaries, security policies, incident response commitments, and MFA support. For cloud platforms and SaaS tools, Ligala Tech Pte should verify tenant-level logging, role-based access, encryption, and administrative control options. For vendors with access to production or legal data, use a formal access request process requiring named users, time limits, and approval from the Business Service Owner and Security Lead. Broad roles such as full administrator access should be avoided unless a specific exception is approved.
Operationally, Ligala Tech Pte should use centralized identity controls wherever possible, including single sign-on, MFA, and separate vendor accounts. Privileged vendor access should be granted only when necessary, recorded in an access log, and reviewed frequently. For cloud services, role naming and permission boundaries should be assessed before production use, and any inherited high-risk permissions should be reduced or replaced with custom least-privilege roles. Offboarding should include disabling accounts, rotating shared secrets, revoking API keys, and confirming data deletion or return. A small organization can manage this effectively through a maintained register, recurring review calendar, and a standard vendor checklist.
7. Monitoring, Evidence, and Compliance
Ligala Tech Pte shall monitor vendor compliance through periodic reviews, evidence collection, and issue tracking. High-risk vendors, including those with access to production systems, personal data, or privileged functions, must be reviewed at least quarterly. Lower-risk vendors must be reviewed at least annually. Reviews should confirm that the vendor’s scope has not expanded, that access remains appropriate, that incidents were reported on time, and that any agreed remediation actions are complete. Material changes such as acquisitions, security incidents, service changes, or data location changes must trigger an out-of-cycle review.
Evidence must be retained in a centralized vendor file and may include risk assessments, privacy reviews, security questionnaires, signed contracts, data processing terms, access approvals, logs of privileged activity, review meeting notes, incident notices, remediation trackers, and deletion certificates. Metrics should include the number of active vendors by risk tier, the percentage of vendors with current reviews, time to deprovision after termination, number of open vendor remediation items, and number of privileged accounts under third-party control. These metrics help a small organization identify where controls are weakening.
Escalation must occur when a vendor lacks required evidence, fails to remediate material findings, refuses contractual terms, or shows unsafe access patterns. Any unresolved critical issue affecting production, personal data, or privileged access must be escalated to the Managing Director and Security Lead within one business day. Repeated policy violations, such as excessive permissions or missing incident notification, must result in access suspension or relationship review. Noncompliance may lead to contract restrictions, additional controls, or termination.
8. Exceptions
Exceptions to this policy are permitted only when a business justification exists, the risk is understood, and compensating controls are documented. The request must be submitted by the Business Service Owner, reviewed by the Security Lead and Privacy / Data Protection Lead when personal data is involved, and approved by the Managing Director for high-risk deviations. No exception may be self-approved by the vendor or by the individual requesting the service.
Each exception must document the requirement being waived, the reason for the exception, the residual risk, the compensating controls, the approval date, and the expiry date. Exceptions should be time-bound and normally not exceed 90 days unless a longer period is explicitly approved with justification. Examples may include temporary privileged access during incident response or urgent business continuity events, provided access is narrowed and closely monitored.
Expired exceptions must be either closed by returning to compliance or renewed through a fresh review. The Procurement or Vendor Owner must track exception expiry dates and notify the relevant approver at least 10 business days before expiration. A vendor may not continue operating under an expired exception without documented reauthorization.
9. Review and Maintenance
This policy must be reviewed at least annually by the Security Lead, Privacy / Data Protection Lead, and Procurement or Vendor Owner, with final approval by the Managing Director. A review must also occur whenever there is a major change in legal obligations, significant cloud architecture change, a serious vendor incident, or repeated control failures indicating that the policy is not effective. Because Ligala Tech Pte is small, the review process should be concise but deliberate, and it should capture both compliance lessons and operational burdens.
During review, the organization should assess whether the risk tiers remain appropriate, whether contract clauses are still sufficient, whether monitoring frequency matches actual vendor risk, and whether controls are working in practice. Open findings, such as excessive administrator permissions, should directly inform policy updates and implementation changes. Any revision must be version-controlled, communicated to affected staff, and incorporated into onboarding, procurement, and access workflows.
The policy owner should maintain a change log documenting the reason for updates, key revisions, approval date, and effective date. Staff involved in vendor management should receive notice of material changes and, where needed, targeted refresher guidance. Continued use of the policy depends on consistent application; if implementation gaps are observed, the policy must be refined to be more executable rather than less stringent.
10. Related Standards
Singapore PDPA is directly relevant because many vendors will handle personal data on behalf of Ligala Tech Pte. This policy supports PDPA-aligned obligations by requiring reasonable protection arrangements, contractual controls, purpose limitation, access restriction, breach notification readiness, and secure deletion or return at the end of a relationship. It also reinforces accountability by ensuring that third parties are not treated as outside the organization’s responsibility when they process company-managed personal data.
ISO 27001 is relevant because vendor management is a core information security control area requiring risk treatment, supplier oversight, and continual improvement. This policy translates ISO 27001 principles into practical requirements for due diligence, access management, logging, monitoring, incident handling, and offboarding. It also helps evidence that external dependencies are governed within the information security management system rather than handled informally.
Together, these standards shape the policy into a unified privacy and security control framework. PDPA drives lawful and responsible handling of personal data, while ISO 27001 drives systematic management of supplier-related information security risk. For Ligala Tech Pte, the combined effect is especially important because legal technology services may expose sensitive client material and require cloud-based administration. This policy ensures that external trust is earned, documented, monitored, and withdrawn when no longer justified.
Comments
0 comments
Please sign in to leave a comment.