The short answer
Identify the necessary access, who approves it and when revised by each supplier. Also check underlying dependencies and agreements at the end of the cooperation.
Make an overview that goes beyond contracts
A supplier may have access to an application, network device, cloud environment or management portal. Ask each internal owner which third parties provide support and through which route. Include temporary projects. The survey should show what someone can technically do, not just what service has been ordered.
Limit access to the agreed scope
Discuss which systems are really needed and whether access should remain permanently available. Use personal accounts, appropriate authentication and technical limitations where possible. Give extension of rights an owner and an evaluation moment. A description in a contract shall not replace the check on the actual configuration.
Speaking of incidents and changes in advance
Who calls who is used as a suspect in a supplier account, and how is suspicious use detected? What information can the supplier provide and who decides to interrupt access? The NCSC principles for chain security emphasize insight into dependencies and collaboration with suppliers. Translate that into agreements your own team can apply.
Also close the cooperation technically
An terminated contract does not automatically mean that accounts and links disappear. Check access, keys, management rights and transfer of documentation. JViT helps integrate such controls into your security management, so that external expertise is available with clear responsibilities.
Discuss this with your team
- Which parties have technical access?
- Who approves new rights?
- Who can be reached in an incident?
- Is access at termination demonstrably withdrawn?



