De audit is gebaseerd op praktijkervaring en best practices uit ISO 27001, NIST, TISAX en waar relevant CTPAT-richtlijnen voor logistieke en fysieke supply chain security. We richten ons op zes kerngebieden die samen een compleet beeld geven van security in de keten.
The audit draws on field experience and best practices from ISO 27001, NIST, TISAX and, where relevant, CTPAT guidance for logistics and physical supply chain security. We cover six core domains that together provide a complete picture of supply chain security.
1. Governance, risk & compliance
1. Governance, risk & compliance
Hoe is security georganiseerd bij de leverancier? We kijken naar beleid, verantwoordelijkheden, risicomanagement en compliance met relevante normen.
How is security organised at the supplier? We review policies, responsibilities, risk management and compliance with relevant standards.
- Informatiebeveiligingsprogramma, rollen & verantwoordelijkheden.
- Securitybeleid, standaarden en procedures.
- Risico-analyse, interne audits en compliance-rapportage.
- Information security programme, roles & responsibilities.
- Security policies, standards and procedures.
- Risk assessment, internal audits and compliance reporting.
2. Manufacturing & operations security
2. Manufacturing & operations security
Bescherming van materialen, IP en producten in de fabriek: van inbound-materialen tot scrap-management en counterfeit-preventie.
Protection of materials, IP and products on the shop floor: from inbound material to scrap management and counterfeit prevention.
- Tracking & traceability van materialen en orders.
- Beveiliging van inventory en handling van proprietary items.
- Segregation of duties, scrap-beheer en anti-counterfeit maatregelen.
- Tracking & traceability of materials and orders.
- Security of inventory and handling of proprietary items.
- Segregation of duties, scrap management and anti-counterfeit controls.
3. Informatie- & infrastructuurbeveiliging
3. Information & infrastructure protection
Bescherming van uw data, ontwerpen, firmware en systemen bij de leverancier – inclusief netwerkbeveiliging en logging.
Protection of your data, designs, firmware and systems at the supplier – including network security and logging.
- Dataclassificatie, handling en encryptie (rust & transit).
- Toegangsbeheer, netwerkbeveiliging en configuratiemanagement.
- Logging & monitoring, back-ups, retentie en veilige vernietiging.
- Data classification, handling and encryption (at rest & in transit).
- Access control, network security and configuration management.
- Logging & monitoring, backups, retention and secure disposal.
4. Logistics, storage & physical security
4. Logistics, storage & physical security
Hoe worden goederen opgeslagen, verplaatst en beschermd? We kijken naar magazijnen, transitsecurity, fysieke controlemaatregelen en waar relevant CTPAT-principes.
How are goods stored, moved and protected? We review warehouses, transit security, physical safeguards and, where relevant, CTPAT principles.
- Fysieke beveiliging van warehouses en productieruimtes.
- Shipping & receiving, transport-beveiliging en seal-procedures.
- Afstemming met CTPAT-principes voor transport, seal-controle, toegangsbeheer en fysieke beveiliging waar relevant.
- Bezoekersbeheer, perimeterbeveiliging en onderhoudsactiviteiten.
- Physical security of warehouses and production areas.
- Shipping & receiving, transit security and seal procedures.
- Alignment with CTPAT principles for transport, seal control, access management and physical security where relevant.
- Visitor management, perimeter protection and maintenance activities.
5. People, access & incident management
5. People, access & incident management
Medewerkers, awareness en reactie op incidenten zijn cruciaal. We toetsen screening, training, contracten en incidentprocessen.
People, awareness and incident response are critical. We review screening, training, contractual controls and incident handling.
- Pre-employment checks, NDA’s en contractuele security-clausules.
- Security-training en awareness voor productie, IT en logistiek.
- Incidentidentificatie, melding, respons en herstel.
- Pre-employment checks, NDAs and contractual security clauses.
- Security training and awareness for production, IT and logistics staff.
- Incident identification, reporting, response and recovery.
6. Third parties, cloud & security engineering
6. Third parties, cloud & security engineering
Leveranciers werken zelf ook weer met cloud, 3rd tier partners en ontwikkelteams. We beoordelen hoe zij daarmee omgaan en welke eisen zij doorvertalen.
Suppliers in turn rely on cloud, 3rd tier partners and engineering teams. We assess how they manage those dependencies and propagate your security requirements.
- Contractuele eisen richting onderaannemers en cloudproviders.
- Secure design & development voor firmware, tools en portals.
- Toezicht op downstream-risico’s en kwetsbaarheidsbeheer.
- Contractual requirements for subcontractors and cloud providers.
- Secure design & development for firmware, tools and portals.
- Oversight of downstream risks and vulnerability management.