LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Vendor Management Policy

Public security and assurance reference

POL-18: Vendor Management Policy

Purpose

This policy establishes the requirements for managing third-party vendors to protect LNC Nexus systems and data. It ensures that vendor relationships are secure and compliant.

Scope

This policy applies to all third-party vendors who interact with LNC Nexus hosted, private, or self-managed deployments.

Policy Statements

Vendors shall be vetted before engagement. Security requirements must be included in contracts. In self-managed deployments, customers are responsible for managing their vendors; LNC Nexus provides the framework but not the enforcement. Regulated data handling requires additional vendor controls. No vendor shall have access without proper vetting and agreements.

Roles and Responsibilities

The Security Team defines vendor management standards and monitors compliance. Procurement implements vetting and contracting procedures. Department heads ensure compliance in their areas. Users follow vendor interaction procedures.

Evidence and Review

Vendor vetting records, contract reviews, and audit reports serve as evidence of compliance. The Security Team conducts periodic reviews of vendor management practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Vendor access may be suspended immediately upon detection of a violation.

POL-1 (Access Control Policy), POL-8 (Information Security Policy), POL-16 (Risk Management Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft