« Back to DataSecurityPolicies.com

Outsourcing Policy

I wrote a generic outsourcing policy for a presentation I’m giving on outsourcing security services.

Here’s the general outline:

  • Purpose
  • Scope/Applicability
  • Policy Statement
    • Board and Management Responsibility
    • Risk Mitigation Strategies: Outsourcing Team
    • Business Case
    • Due Diligence
    • Business Continuity Management (BCM)
    • Contractual Agreements
    • Management and Control of the Outsourcing Relationship
    • Offshoring
    • Final Approval

Here’s an excerpt:

1.0 Purpose

The purpose of this policy is to establish the requirements for identifying, justifying, and implementing outsourcing arrangements for any Organization XYZ function.

2.0 Scope

This policy applies to all workforce members within Organization XYZ. It must be followed whenever Organization XYZ functions are outsourced.

3.0 Policy

To conduct operations as effectively and efficiently as possible, Organization XYZ may find it advantageous to outsource (use outside contractors for) certain functions. To ensure compliance with security objectives, these requirements must be followed:

You can download a copy of the policy here: Outsourcing Policy

One Response to “Outsourcing Policy”

  1. Alexander Preston on November 12th, 2008 at 2:45 pm

    rfb32kehdj8w60g4

Leave a Reply