供應商審查工作流
如何建立 ICT 供應商資安盡職調查證據包
把核准的軟體供應商文件整理成可追溯的證據包,清楚標示來源、適用範圍、缺口、負責人與複審日期。
關於這篇指南
工作流程
在採購或續約前審查單一 ICT 或軟體供應商的採購、資安與 IT 負責人
9 分鐘閱讀
01
讓每個供應商主張都連回核准文件、日期、修訂與適用服務範圍。
02
分開記錄資料存取、營運韌性、資安佐證、依賴關係與尚未回答的問題。
03
為證據包指定負責人與複審日期,不把舊問卷答案當成永久事實。
完整示範
建立 ICT 供應商盡職調查證據包
這是三個檔案的虛構盡職調查練習:分開供應商聲明與實際證據,找出缺口,再把未決事項交給採購和法務審查。
試做這個任務
只根據三個來源檔,列出實際存在的證據與所有重要缺口,並說明為什麼採購或法務負責人必須暫緩決定。每個結論都用 [[filename]] 引用。
預期推理
供應商提供的是說明與問卷回答,不是獨立或合約證據。刪除證據、資料駐留、子處理者、保證報告與簽署條款都缺少;不能推出認證或可接受風險結論。
為什麼要保持這些內容連結
一份不完整的供應商資料可以手動核對。當問卷修訂、合約、證據附件與人工審查決定需要保持可追溯,又不能虛構保證時,來源連結的盡職調查 wiki 才有幫助。
審查邊界
逐項核對聲明是否有附件證據,特別看刪除紀錄、駐留資料、子處理者與合約;不要把聲明當認證,採購與法務仍需判斷。
在 Wenlan 裡查看這個範例
Wenlan v0.18.3 介面,呈現隔離測試後讀回的資料。來源是虛構教學資料,參考答案為這次練習人工編寫;畫面沒有展示 AI 自動生成或審批完成。
引用的來源變更後,Wenlan 將頁面標記為過期,正文仍保留原文。這裡的「updating…」表示等待重建,不代表已完成修正。請先檢查變更的來源,再重建並審查新答案。
來源檔案
打開檔案即可閱讀完整的人工編寫 Markdown。
三種語言檢視使用相同的人工編寫英文來源資料集。
01supplier-profile.mdMicaGrid Systems — fictional supplier profile
# MicaGrid Systems — fictional supplier profile MicaGrid Systems is a fictional hosting supplier for this teaching exercise. Its profile says it can host application workloads in an EU region and describes encryption in transit and at rest. The profile is a supplier-authored description. It includes no signed contract, independent assurance report, certificate, data-flow diagram, or evidence that the described options are enabled for a particular customer.
02security-questionnaire.mdMicaGrid Systems — questionnaire response
# MicaGrid Systems — questionnaire response Status: fictional response, evidence review pending. The supplier states that customer data can be deleted within 30 calendar days after a written request. It has not attached a deletion test, retention configuration, or service-specific record. Data residency details and the current subprocessor list are unanswered. These statements are questionnaire answers, not legal or compliance certification.
03procurement-review.mdProcurement review checklist
# Procurement review checklist The reviewer has a supplier profile and a questionnaire but no signed data-processing terms, independent assurance report, deletion evidence, residency confirmation, or subprocessor list. Keep the supplier decision on hold until the responsible procurement and legal owners review the missing evidence and contract terms. Do not infer certification, regulatory approval, or acceptable risk from the supplier's statements. A human owner must record any final decision.
參考答案
Reference answer: a supplier statement is not a certification
The packet contains supplier descriptions and a questionnaire statement about deletion within 30 days, but no independent or contract evidence. Residency and subprocessors are unanswered, and procurement and legal owners must review the gaps before deciding; no certification or compliance conclusion is warranted.
MicaGrid Systems — due-diligence reference
Evidence present
The fictional supplier profile describes EU-region hosting and encryption in transit and at rest, but it is a supplier-authored description with no attached contract, assurance report, certificate, data-flow diagram, or customer-specific enablement evidence. supplier-profile.md
The questionnaire states that data can be deleted within 30 calendar days after a written request, but provides no deletion test, retention configuration, or service-specific record. Residency and the current subprocessor list are unanswered. security-questionnaire.md
Decision boundary
This is an evidence gap, not a legal or compliance certification. The missing terms, assurance report, deletion evidence, residency confirmation, and subprocessor list keep the decision on hold. Procurement and legal owners must review the evidence and contract before recording any final decision. procurement-review.md
變更後的來源: security-questionnaire.md
這項變更後的預期更新
The reference's statement that the supplier says data can be deleted within 30 calendar days becomes stale. Revision 2 removes that fixed period and makes timing dependent on the service and written agreement, so deletion timing is now unknown. The missing evidence, no-certification boundary, hold status, and human procurement/legal review remain unchanged.
# MicaGrid Systems — questionnaire response, revision 2 Status: fictional response, evidence review pending. The supplier cannot state a fixed deletion period. Deletion timing depends on the service and written agreement, and no deletion test, retention configuration, or service-specific record is attached. Data residency details and the current subprocessor list remain unanswered. These statements are questionnaire answers, not legal or compliance certification.
01
先說結論:一次審查只處理一個供應商與服務範圍
先固定供應商、產品或服務、採購或續約決策、資料存取範圍、審查人員與核准來源。證據包至少要記錄來源文件、修訂、適用範圍、韌性與資安佐證、相依服務、缺口、待確認事項、負責人與複審日期。
無法由來源支持或已過期的主張要明確標為未驗證。最後的採購判斷仍由組織內的採購、資安、法務與隱私負責人依既有制度作出。
02
把問卷、政策與架構文件拆成可檢查的證據
供應商審查常把現行資安政策、舊問卷、架構圖、驗證聲明與郵件補充混在同一張表。若沒有日期與適用範圍,摘要再流暢也無法回答某項控制是否適用於正在採購的服務。
- 建立來源登錄:保存文件名稱、版本、日期、提供者、適用服務與允許使用範圍。
- 逐項記錄主張:連到確切段落,分開供應商陳述、審查者解讀、殘餘風險、矛盾與缺件。
- 標示資料與系統存取:記錄資料類型、權限、儲存位置、保留方式與次處理者或關鍵依賴。
- 設定複審:來源或服務範圍改變時,先把依賴該證據的結論標為過期,再交由具名負責人確認。
有界的供應商證據工作流
wenlan status
wenlan sources add ~/Reviews/approved-supplier-docs
# 在 Wenlan plugin client 中:
/distill <供應商與審查範圍>
/pages <供應商證據包>
/lint
/curate03
一份可複審的供應商證據包應包含什麼
把每一項內容標為目前有效、過期、互相矛盾、缺乏支持或待補件,並保留證據負責人、審查者、相依服務與下次複審日期。問卷答案只能算供應商提供的一項主張,不能直接等同控制已有效落實。
即使不使用 Wenlan,這份來源登錄、缺口清單與複審欄位仍可作為採購會議中的獨立工作產物。
04
Wenlan 的能力與安全邊界
Wenlan 能把核准的 Markdown、文字、可擷取文字的 PDF、資料夾與唯讀 Obsidian 來源,整理成有來源的 Pages,並顯示引用、修訂、過期狀態、lint 與人工審查。
Wenlan 不會驗證認證真偽、不提供法律或隱私意見、不發現供應商、不爬取網站、不做即時監控或弱點掃描、不自動評分,也不核准或拒絕採購。敏感文件仍須留在組織核准的存取控制中。
讓一次供應商審查可追溯
選定一個供應商與服務範圍,連接核准證據,並在決策會議前保留所有過期或缺乏支持的主張。
常見問題