Software and SaaS
The applications the business runs its processes in, almost always delivered as a subscription on someone else's infrastructure. The vendor holds the data and the roadmap; the contract holds what you can ask back.
Categories in this family
7- Backup and recovery critical
The copies of everything, and the service that restores them; the last line when a primary system or a ransomware event takes the rest. - CRM and customer platform important
Where customer records, cases and campaigns live, and usually where personal data concentrates. - Collaboration, email and productivity critical
Email, calendars, documents, chat and meetings: the tools every employee works in all day. - ERP and finance software critical
The system of record for the ledger, purchasing, billing and financial reporting. - HR and payroll software important
The employee record, payroll calculation and the HR processes around them, holding the most sensitive personal data in the business. - Identity and access management critical
The service that decides who can sign in to what; every other system trusts it. - Security tooling important
Detection, prevention and logging tools: the controls the security function runs and the auditors ask to see.
What reaches this family
| DORA | Attaches to contractual arrangements for ICT services: cloud, software, network, managed services and data feeds. A supply of hardware, a bank or a courier is recorded in the register only where a service element sits in the contract. On every vendor here: DORA Art. 28, DORA Art. 30. |
|---|---|
| NIS2 | Attaches to every direct supplier and service provider of the entity, whatever it supplies; the depth of the assessment follows the access and the criticality. On every vendor here: NIS2 Art. 21(2)(d), NIS2 Art. 21(3), NIS2 Art. 24. |
| SP 800-161 | Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access. On every vendor here: SP 800-161 SR-6, SP 800-161 SR-8, SP 800-161 SA-4, SP 800-161 SR-13, SP 800-161 SA-9, SP 800-161 AC-20, SP 800-161 IR-6. |
| ISO 27001 | Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default. On every vendor here: ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.22, ISO 27001 5.23, ISO 27001 5.21. |
Register the vendors in this family
Paste the list; every vendor in this family is placed in its category, given its share of spend and systems and the country it lands in, and carries the obligation rows above. Eight vendors free, no account.
Build my vendor register