The purpose of this Third-Party Vendor Management Policy is to establish guidelines and procedures for the selection, engagement, and ongoing management of third-party vendors by the Archdiocese of Baltimore.
This policy ensures that all third-party vendors adhere to the Archdiocese’s standards for security, privacy, and compliance to safeguard sensitive information and maintain the organization’s reputation.
This policy applies to all employees, volunteers, contractors, and affiliates of the Archdiocese of Baltimore who engage with or hold responsibilities related to third-party vendors.
1000.3.1 Due Diligence
1000.3.2 Vendor Evaluation Criteria
1000.4.1 Security and Privacy Requirements
1000.4.2 Data Handling and Processing
1000.4.3 Right to Audit
1000.5.1 Vendor Performance Monitoring
1000.5.2 Incident Response and Business Continuity
1000.6.1 Policy Requirement
Only Microsoft-certified applications may be integrated or utilized within the Archdiocese’s Microsoft Azure Enterprise environment. Use of non-Microsoft-certified third-party applications is prohibited unless a formal exception is granted per section 1000.6.4.
1000.6.2 Security & Compliance Rationale
1000.6.3 Operational Enforcement
1000.6.4 Exceptions & Risk Assessment
1000.6.5 Non-Compliance
1000.7.1 Policy Requirement
All Archdiocesan parishes, schools, and affiliated centers must have their registered internet domain names managed within the Archdiocese’s centralized Cloudflare account. No entity shall independently register or manage domains outside of this centralized environment.
1000.7.2 Purpose and Rationale
1000.7.3 Implementation Requirements
1000.7.4 Exceptions and Transitional Provisions
Procedures will be established to ensure a secure and orderly transition and retrieval of all Archdiocese-owned data and assets upon vendor contract termination or expiration.
Failure to comply with this Third-Party Vendor Management Policy may result in contract termination, legal action, or disciplinary measures, depending on the severity and frequency of non-compliance.
This policy will be periodically reviewed and updated by the Technology Department to ensure continued alignment with evolving security risks, regulatory requirements, and organizational needs.
