Home / Rules / The SPECIMEN organisation's own procedure / SSP-5 Supplier access
SSP-5 Supplier access
Supplier staff get named individual accounts only, approved by the system owner, with multi-factor authentication and an expiry of no more than 90 days. Shared accounts are not issued. Privileged access needs the CISO's approval.
The SPECIMEN organisation's own procedure (in the scenario inputs, supplier-security-procedure.md); no external clause decides this step.
Steps that cite it
- KC-01 S6 Decide the vendor's access
Accepted citation forms are listed on the answer format page.