SPECIMEN. Invented organisation, invented procedure, for testing only.
# Kestrel Bay Franchise Group: Supplier Security Procedure (SSP), version 3, approved 1 July 2026

SSP-1 Tiering. Tier 1: the supplier will store or process Confidential or Restricted information, or will hold privileged access to our systems. Tier 2: Internal information only. Tier 3: no access to our information or systems.
SSP-2 Assessment. Tier 1 and Tier 2 suppliers are security-assessed before any contract is signed or any information is shared.
SSP-3 Contract clauses for Tier 1. C1 security requirements; C2 notification to us of any security incident affecting our information within 48 hours of the supplier becoming aware; C3 right to audit or an annual independent assurance report; C4 our prior approval of subcontractors who handle our information; C5 return and deletion of our information at exit; C6 confidentiality.
SSP-4 Accepted assurance for Tier 1. An ISO/IEC 27001 certificate whose scope covers the service, or a SOC 2 Type 2 report whose period ended within 12 months before the assessment date and whose system description covers the service we use. Complementary user entity controls (CUECs) in the report are mapped to our own controls before go-live.
SSP-5 Supplier access. Named individual accounts only, approved by the system owner, multi-factor authentication, expiry of no more than 90 days. No shared accounts. Privileged access needs the CISO's approval.
SSP-6 Cloud services. A supplier that delivers a cloud service also gets an exit plan (data return format, deletion confirmation, timeframe) recorded before go-live.
SSP-7 Review. Tier 1 suppliers are reviewed every 12 months from approval; Tier 2 every 24 months.
SSP-8 Approval authority. The onboarding assistant may approve Tier 2 and Tier 3 suppliers. Tier 1 approvals, and any privileged access, go to the CISO with the assistant's recommendation.
