GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

VND-007 Vendor Access Controls

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Vendor and third-party access to organisational systems, networks and data is governed by the principle of least privilege. Vendor access is formally authorised, time-bound, monitored, and reviewed. Privileged vendor access (e.g. remote support, admin credentials) is subject to additional controls including session recording, just-in-time provisioning, and multi-factor authentication.

Rationale

Third-party access is a major source of data breaches. Vendors with standing, unmonitored access to production systems represent a persistent risk that is disproportionate to operational need.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (10)

UEM-14Third-Party Endpoint Security Posturefull
UEM-14Third-Party Endpoint Security Posturefull
GDPR-Art.29Processing Under Controller Authoritypartial
5.19Information security in supplier relationshipsinformative
5.20Addressing information security within supplier agreementsinformative
NIS2-CIR-11.2Management of Access Rightsinformative
NIS2-CIR-6.7Network Securityinformative
MA-5Maintenance Personnelpartial
SR-7Supply Chain Operations Securitypartial
CC9.2Vendor and Business Partner Risk Managementinformative

Evidence (2)

logtechnicalautomated

Vendor access audit logs demonstrating that third-party access to production systems is logged, time-limited, and reviewed.

Example: PAM or privileged access log export (CyberArk / AWS CloudTrail IAM events / Teleport session logs), showing all vendor access sessions in the last 90 days with: vendor/user identity, session start and end time, systems accessed, and session recording reference

Test: Request vendor access logs for the last 90 days. Verify: (1) all vendor access sessions are logged with user identity, timestamp, and systems accessed, (2) no active standing vendor accounts exist that are not associated with a current vendor engagement, (3) session durations are consistent with declared purposes (no unexplained long-running sessions), (4) privileged sessions have session recordings available.

configurationtechnicalautomated

IAM or PAM configuration demonstrating that vendor accounts are provisioned with least-privilege permissions, require MFA, and are time-limited.

Example: IAM policy export for vendor-associated roles (AWS IAM / Okta group policies), showing restricted permissions scoped to minimum required resources, MFA enforcement enabled, and time-bound access (session expiry / access expiry dates configured in PAM solution)

Test: Review IAM configurations for all active vendor accounts. Verify: (1) all vendor accounts have MFA enforced, (2) permissions are scoped to the minimum required for the vendor's stated purpose (no AdministratorAccess or equivalent granted to vendors), (3) access expiry dates are set and actively managed, (4) no vendor accounts have access that extends beyond the contractual relationship.

Questions (2)

boolean

Is every vendor and third-party access grant formally authorised before access is enabled?

Vendor accounts must enforce MFA, have scoped permissions (no broad administrative access), and be time-bounded. Privileged vendor sessions should be logged and, where possible, recorded.

multi

Which controls are applied specifically to privileged vendor access (e.g. remote support, admin credentials)?

Multi-factor authentication enforced for all vendor accountsJust-in-time (JIT) access provisioning: access is granted only for the duration of the support activitySession recording for all privileged vendor sessionsPrivileged Access Management (PAM) solution mediating all vendor privileged accessAccess review conducted each time a vendor engagement is renewed or modifiedVendor accounts reviewed and deprovisioned when the engagement endsNone of the above

JIT provisioning, MFA, and session recording are the expected standard for privileged vendor access. Standing, unmonitored vendor accounts with broad access are a high-risk exposure.