In Netflix's The Diplomat (2023), Ambassador Kate Wyler does not wing her relationships with foreign governments. She operates inside a framework of protocols, obligations, and documented agreements. When a crisis hits, she knows exactly what her options are and what the rules of engagement require. Without that framework, every new incident becomes a scramble. Your vendor relationships work the same way. When something goes sideways with a service provider, a documented policy tells you exactly what to do next.
What Is Establish and Maintain a Service Provider Management Policy?
It is a written, organization-approved policy that defines how you manage every third-party service provider that touches your data or your infrastructure. Not just the big ones. All of them.
The CIS text is straightforward: "Establish and maintain a service provider management policy. Ensure the policy addresses the classification, inventory, assessment, monitoring, and decommissioning of service providers. Review and update the policy at least annually, or when significant enterprise changes occur that could impact this Safeguard."
The operative word is "maintain." Writing it once and filing it away does not count.
Why It Matters
Most organizations have no idea how many third parties have access to their systems or data. Ask your team to name every vendor with a live connection to your environment. The number they give you is probably wrong, and almost certainly low.
Breaches through third parties are not rare events. They are a primary attack vector. Attackers know that your vendors may have weaker controls than you do, and they use that gap. A service provider management policy does not prevent every incident, but it ensures you know who your vendors are, what they can access, and what your obligations are when something goes wrong.
The policy also gives you something you need for audits, contract negotiations, and incident response: a documented, repeatable process. That is worth a lot.
Key Details or How It Works
- The policy must cover the full lifecycle: how you classify providers, how you build and maintain an inventory, how you assess them before and after onboarding, how you monitor them during the relationship, and how you exit cleanly when the relationship ends.
- Classification matters. Not every vendor carries the same risk. A provider handling payroll data is not the same as the vendor who ships you office supplies. Your policy should define tiers or categories so you can apply proportionate scrutiny.
- Inventory is not optional. You cannot manage what you have not documented. The policy should require a current, maintained list of all active service providers.
- Assessment is a checkpoint, not a one-time event. The policy should specify what you evaluate before onboarding and at regular intervals during the relationship.
- Monitoring keeps the assessment current. Things change. Vendors get acquired, change personnel, or have incidents of their own. The policy should describe how you stay informed.
- Decommissioning is the part most organizations skip. The policy needs to address what happens when you offboard a provider: access revocation, data return or destruction, contract closeout.
- Annual review is the floor, not the ceiling. Review the policy when major changes happen, such as a merger, a new regulatory requirement, or a significant shift in your vendor landscape.
How to Implement Establish and Maintain a Service Provider Management Policy
- Start with the inventory. Before you can write a policy that works, you need to know what you are managing. Pull together a list of every current service provider. Include cloud platforms, SaaS tools, managed service providers, and any third party with access to your systems or data. This list becomes the foundation for everything else.
- Define your classification tiers. Decide how you will categorize providers by risk level. A simple approach: tier by the sensitivity of data accessed and the criticality of the systems involved. Document the criteria clearly so the classification process is consistent and repeatable.
- Draft the policy using the five lifecycle elements. Write a policy that explicitly addresses classification, inventory, assessment, monitoring, and decommissioning. Use plain language. Assign ownership for each element. The CIS policy templates are a solid starting point.
- Get the policy approved and socialized. A policy that lives in a shared drive and nobody knows about is not a policy. Get formal approval from leadership, and make sure the teams who work with vendors know it exists and what it requires of them.
- Build the review cycle into your calendar. Set a recurring annual review. Assign an owner. When significant enterprise changes happen, such as acquisitions, new lines of business, or major vendor changes, trigger an out-of-cycle review rather than waiting for the scheduled date.
- Test it against a real scenario. Walk through a hypothetical vendor incident using your policy as the guide. Can you answer the key questions quickly? Who holds the data? What is the notification obligation? How do you revoke access? If the policy does not answer those questions, it needs more work.
Final Thoughts
Ambassador Wyler does not improvise her way through a diplomatic crisis. She has a framework, and that framework is what keeps a bad situation from becoming a catastrophe. Your service providers are relationships you depend on, and some of them have keys to your most sensitive systems. A written policy is not bureaucratic overhead. It is the playbook you will want in your hands when something goes wrong.
Resources
Here is a link to the Policy Templates provided free of charge from the fine folks at the Center for Internet Security.
Looking for even more detail? Here you go. If this still does not satisfy your curiosity, DM me.
Official CIS Text
CIS Control 15: Service Provider Management Develop a process to evaluate service providers who hold sensitive data, or are responsible for an enterprise's critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately.
CIS Safeguard 15.2: Establish and Maintain a Service Provider Management Policy Establish and maintain a service provider management policy. Ensure the policy addresses the classification, inventory, assessment, monitoring, and decommissioning of service providers. Review and update the policy at least annually, or when significant enterprise changes occur that could impact this Safeguard.
Shameless Marketing Information
Gotham Technology Group helps organizations build and operationalize third-party risk and vendor management programs, from policy development through ongoing monitoring. If your vendor list has grown faster than your oversight process, let's talk.