Third Party Policy
Supply Chain Security Policy
Manage risk introduced through software, hardware, and service supply chains.
Summary
Policy overview
Scope
Build inputs, third-party libraries, managed services, and delivery partners.
Objectives
- Verify provenance of build inputs
- Maintain dependency inventory
- Verify patches before promotion
- Flow down security requirements to subcontractors
What the policy covers
- Dependencies come from trusted registries and are pinned.
- Critical components receive provenance review.
- Patches are validated before promotion.
- Subcontractors inherit applicable security requirements.
Governance
Aligned to NIST SP 800-161 C-SCRM concepts and reviewed alongside vendor management.
Framework references
- NIST SP 800-161
- NIST SSDF SP 800-218
These are public governance summaries. Full policy text, operational procedures, runbooks, and configuration standards are not published and are provided under NDA or contract where a review requires them.
Related
More Third Party policies
Vendor Management Policy
Ensure vendors and subprocessors meet security expectations before and during use.
IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.
Requesting security documentation?
Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.