Data centers depend on external organizations for generators, UPS systems, cooling, fire systems, access control, software, networks, cleaning, security, construction and specialist maintenance. Third-party access is therefore necessary, but unmanaged supplier access can create persistent security and compliance exposure.
Perform due diligence before access
Supplier evaluation should consider the sensitivity of the service, required access, dependency on remote connectivity, subcontractors, data handled, support model and ability to meet security obligations. The depth of review should be proportional to risk.
Put security requirements in the agreement
Contracts or service agreements should define applicable security responsibilities, confidentiality, access restrictions, incident notification, use of subcontractors, evidence requirements, retention, return of assets and offboarding obligations where relevant.
Separate company approval from individual access
Approving a vendor does not mean every vendor employee should have unrestricted access. Individual technicians should be identified, authorized for the required period and given only the physical and logical permissions needed for the approved task.
Control remote support
Remote vendor access to BMS, UPS management, security systems or other infrastructure should be explicitly authorized, authenticated and logged. Persistent always-on accounts should be avoided where a controlled on-demand method is practical.
Manage privileged activity
When a supplier needs administrative rights, the organization should know when the session starts, who performs it, what system is affected and when privileges are removed. Change management should apply to configuration changes made by external personnel.
Monitor supplier performance
Supplier assurance should not end at contract signature. Review security incidents, access anomalies, missed maintenance, repeated defects, audit findings, unsupported software and failure to meet agreed evidence requirements.
Control subcontractors
Critical vendors may rely on subcontractors. The organization should understand whether contractual security requirements flow down to them and whether subcontractor personnel are subject to equivalent authorization and access controls.
Offboarding
- Disable physical and logical credentials.
- Recover badges, keys and tokens.
- Remove remote-access accounts.
- Return or destroy controlled information as required.
- Transfer configuration files and documentation.
- Review any shared secrets or passwords that require rotation.
- Confirm no temporary access remains active.
Key takeaway
Third-party risk should be controlled throughout the supplier lifecycle: selection, contracting, onboarding, access, service delivery, monitoring and offboarding. The data center remains accountable for the security of critical operations even when specialist work is performed by another company.
References and Further Reading
- ISO/IEC 27001:2022 and Amendment 1:2024.
- ISO/IEC 27002:2022.
- ISO/IEC 22237-6:2024.