Services
Security protection agreements
Requirements and follow-up in security-protected procurement
A security protection agreement governs the protective security a supplier must maintain when given access to security-sensitive activities or classified information. It is the only mechanism you have to steer a supplier's security work.
We draft the requirements annex, support the level assessment and make sure the agreement can actually be followed up.
When is it needed?
- In security-protected procurement of goods, services or construction
- When a supplier accesses classified information or sensitive premises
- When outsourcing operations, IT or support
- When existing supplier contracts lack protective security requirements
- Before consultation with the supervisory authority
How it works
- 01
Basis
We start from your protective security analysis and the special security assessment for the deal.
- 02
Level
We assess which agreement level and requirements are proportionate to the access granted.
- 03
Requirements
We define requirements for personnel, physical and information security, including subcontractors.
- 04
Follow-up
We set control points, reporting and routines for revoking access.
Common shortcomings
Requirements are written too generally and cannot be verified. A requirement that cannot be checked provides no security.
Subcontractors are forgotten. Access often ends up one step beyond what the agreement regulates.
Follow-up in practice
We propose a simple control programme: what is monitored, how often, by whom and what happens on deviation.
Where needed we support vetting of supplier personnel and exit control at the end of the assignment.
What you get
- A security protection agreement with tailored requirements
- A motivated level assessment linked to consequence
- Requirements for subcontractors and personnel security
- A control programme for the contract term
- A routine for revoking access at the end
Part of Analysis
The agreement builds on the protective security analysis and the special security assessment.
Frequently asked questions
- Who is responsible for the agreement?
- The procuring operator is responsible for having the agreement, setting the right level and following it up throughout the contract.
- Is the agreement enough on its own?
- No. It presupposes a protective security analysis and a special security assessment of the specific deal.
- Must supplier personnel be vetted?
- Yes, if they take part in security-sensitive activities or access classified information.
About to sign a security protection agreement?
Describe the deal and we will come back with a proposed approach.
