Purpose:
Section titled “Purpose:”If a client requests access to their systems for a third party or vendor, this is the approval the client must agree too before access can be granted.
Scope:
Section titled “Scope:”For use with any client requesting access to ncentral.
Responsibility:
Section titled “Responsibility:”vITMs & vCIOs
Completion Criteria:
Section titled “Completion Criteria:”The template is to be edited to match the client and vendor and server access list, then sent to the client for approval. Email of approval should then be saved as a PDF and attached to the ticket record requesting access.
Records:
Section titled “Records:”Approval email from client saved as PDF and attached to the ticket record.
Steps:
Section titled “Steps:”- Use the following template https://centrexdata-my.sharepoint.com/:w:/g/personal/mhicks_centrexit_com/ERiIfJ55STlGoxsVbpmm464BtJAAkeUFcDEUeeH3UIydoQ?e=ySnicn
- Change [Client Name] to match the client
- Change [VENDOR NAME] to match the third party or vendor being given access
- Replace [List of servers of which the vendor will have access] with the specific servers.
Template:
Section titled “Template:”Dear [Client Name],
We are reaching out to formally request your acknowledgment and approval for [VENDOR NAME] granting access to your server. We need your formal approval and acknowledgement of the following:
- [VENDOR NAME] will have access to the following servers:
- [List of servers of which the vendor will have access]
- With this level of access, [VENDOR NAME] will have full administrative access and privileges to these systems, and potentially connected systems, allowing them to manage system configurations, install and update software without any further assistance from centrexIT. It is important to note that this level of access provides them with full control over server resources, data, and settings.
- The Client agrees to release, indemnify, and hold harmless centrexIT from all incidents that may result from this access, including but not limited to the following:
-
Any data breaches or security incidents
-
Unauthorized access or misuse of data
-
Operational disruptions, downtime, or loss of productivity
-
Any other damages or losses incurred by the Client
- The Client acknowledges that the Vendor will be responsible for complying with all applicable laws, regulations, and industry standards related to data security and privacy. [VENDOR NAME] will also be responsible for ensuring that their actions do not compromise the integrity, confidentiality, or availability of the [Client Name] Belardi Wong data and systems. Before proceeding, we kindly ask you to review and confirm your approval of this access. If you have any concerns or would like further clarification on the scope of access and security measures in place, please do not hesitate to reach out.
To proceed with granting access, please reply with Approve or Deny.
Process References:
Section titled “Process References:”- Create a relationship back to related process. Note: Please add KB relationships to core process, process, SOPs or other WIs on the right.