The ComponentSource Group (referred to as "ComponentSource", "we", "us", "our") is made up of numerous individual companies, consisting of:
To ensure protection of the organization's data and assets that are shared with, accessible to, or managed by suppliers, including external parties or third-party organizations such as service providers, vendors, and customers, and to maintain an agreed level of information security and service delivery in line with supplier agreements.
This document outlines a baseline of security controls that ComponentSource expects partners and other third-party companies to meet when interacting with ComponentSource Confidential data.
All data and information systems owned or used by ComponentSource that are business critical and/or process, store, or transmit Confidential data. This policy applies to all employees of ComponentSource and to all external parties, including but not limited to ComponentSource consultants, contractors, business partners, vendors, suppliers, partners, outsourced service providers, and other third-party entities with access to ComponentSource data, systems, networks, or system resources.
ComponentSource will consider and assess risk associated with suppliers and the technology supply chain. Where warranted, agreements with suppliers will include requirements to address the relevant information security risks associated with information and communications technology services and the product supply chain.
ComponentSource will regularly monitor and review supplier service delivery. Supplier security and service delivery performance will be reviewed at least annually.
Changes to the provision of services by suppliers, including changes to agreements, services, technology, policies, procedures, or controls, will be managed, taking account of the criticality of the business information, systems, and processes involved. ComponentSource will assess the risk of any material changes made by suppliers and make appropriate modifications to agreements and services accordingly.
This section outlines the fundamental parameters for managing and mitigating risks related to cloud service usage.
Requests for an exception to this Policy must be submitted to dpm@componentsource.com for approval.
Any known violations of this policy should be reported to group-compliance@componentsource.com. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.
CSTPMP 10/2025