Skip to content

Third Party Policy

Supply Chain Security Policy

Manage risk introduced through software, hardware, and service supply chains.

Summary

Policy overview

Scope

Build inputs, third-party libraries, managed services, and delivery partners.

Objectives

  • Verify provenance of build inputs
  • Maintain dependency inventory
  • Verify patches before promotion
  • Flow down security requirements to subcontractors

What the policy covers

  • Dependencies come from trusted registries and are pinned.
  • Critical components receive provenance review.
  • Patches are validated before promotion.
  • Subcontractors inherit applicable security requirements.

Governance

Aligned to NIST SP 800-161 C-SCRM concepts and reviewed alongside vendor management.

Framework references

  • NIST SP 800-161
  • NIST SSDF SP 800-218

These are public governance summaries. Full policy text, operational procedures, runbooks, and configuration standards are not published and are provided under NDA or contract where a review requires them.

Related

More Third Party policies

IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.

Requesting security documentation?

Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.