1. Introduction
Superfast IT works with a number of trusted suppliers to deliver secure and resilient managed services. This document explains how we assess, monitor and manage these suppliers to ensure they meet our security, operational and compliance expectations.
Our approach aligns with Cyber Essentials Plus, IASME Cyber Assurance, NCSC guidance for Managed Service Providers and the Cyber Assessment Framework (CAF 4).
2. Objectives
Our supply chain management objectives are to:
- ensure suppliers supporting our services meet strong security standards
- maintain resilience and continuity in the supply chain
- identify and manage risks associated with third party services
- ensure suppliers meet contractual, regulatory and confidentiality requirements
- maintain transparency for clients regarding sub-processors used in service delivery
3. Supplier Categories
Critical Service Providers
Suppliers essential for delivery of our services, including:
- cloud service platforms such as Microsoft 365 and Azure
- monitoring and RMM tooling
- backup and disaster recovery vendors
- identity and authentication services
Security and Compliance Providers
Tools and platforms that support governance and security, for example:
- vulnerability scanning tools