Back to AI & Cybersecurity Governance
Current Policy
Board Approved
Third-Party and Vendor Security Policy
Ensures third-party vendors and service providers meet appropriate security standards.
Effective 2026-01-15 Reviewed 2026-01-15
Effective Date
2026-01-15
Last Reviewed
2026-01-15
Version
1.0
Approved by the Board of Directors — Board of Directors on 2026-01-15
Purpose
To ensure that third-party vendors and service providers meet appropriate security standards when handling our organization's data.
Scope
This policy applies to all Inspirational Hope staff, volunteers, contractors, board members, and technologies used in our programs, services, and operations.
Public Policy Commitments
We commit to evaluating vendor security practices before engagement, requiring appropriate data protection agreements, and monitoring vendor compliance.
Roles and Accountability
The Executive Director is responsible for overseeing implementation of this policy. The Board of Directors provides governance oversight and approval. All staff and volunteers are responsible for compliance and for raising concerns when they arise.
Reporting Concerns
Concerns about this policy should be reported to the Executive Director at bethany@inspirationalhope.org or through our confidential reporting process. Retaliation against anyone reporting a concern in good faith is strictly prohibited.
Policy Review Statement
This policy is reviewed at least annually and may be updated as technology, cybersecurity risks, legal requirements, and organizational practices evolve.
Governance policies are reviewed periodically and may be updated as technology, cybersecurity risks, legal requirements, and organizational practices evolve.