Supply Chain Security
The security of Intel’s supply chain is of the utmost importance to Intel, our customers and our existing suppliers. Intel maintains the same policies and procedures, with appropriate localization to meet laws, regulations, and local risks, for all aspects of the supply chain, independent of the physical location. Intel supports appropriate global standards, when available, that are used to establish policies for security and privacy aspects of Intel’s supply chain.
IT Security Policies
All suppliers providing hardware, developing software, managing systems and/or processing data on behalf of Intel must meet the minimum requirements outlined in the Intel Information Security Addendum (ISA), and as applicable in the ISA Appendix A for Cloud Security or the ISA Appendix B for Offshore Development Centers. Intel suppliers are subject to Intel’s data protection and cyber security requirements and all applicable laws, including all applicable data protection and cybersecurity laws and regulations. For suppliers within this scope, the following may also apply:
- Intel, as part of onboarding new suppliers and periodically throughout the agreement, may perform a due diligence risk assessment of a Supplier’s cyber security controls regardless of location, using a combination of internal and industry methods. Supplier will provide reasonable cooperation to Intel by responding to these assessments and attesting to their security controls. Please work with your Intel Account contact to learn more.
Intel Information Security Addendum (ISA)
ISA Appendix A for Cloud Security
ISA Appendix B for Offshore Development Centers
Skill Requirements
To drive improvements product security quality, suppliers are expected to source workers who meet a specified set of security skill requirements. These skill requirements are role-based and apply to all new contracts.
The applicable roles and associated security skill requirements are available for download here; this list may grow over time to comprehend additional roles. The last column in this table provides links to recommended publicly available training courses to help suppliers remediate security skill gaps.
An optional skill assessment tool (quiz) is available, to make it easier for suppliers to identify security skill gaps. There are two versions of the quiz:
- Version to provide to job candidates is available for download here
- Version (with the answers) to assist the supplier in administering the quiz, identifying skill gaps and the remediation plan, is available for download here
It is anticipated that remediation of identified security skill gaps could potentially require several hours of training if the recommended publicly available courses are used. Remediation must be completed no later than the first week after a worker’s assignment to Intel.
Self-Assessment Questionnaire
The Self-Assessment Questionnaire (SAQ) is a risk-assessment tool developed by the Responsible Business Alliance (RBA, formerly known as the EICC), which enables corporations to evaluate specific supply chain risk areas including, labor, health and safety, environment, and ethics.
Security Skill Requirements
To drive improvements product security quality, suppliers are expected to source workers who meet a specified set of security skill requirements. These skill requirements are role-based and apply to all new contracts.
The applicable roles and associated security skill requirements are available for download here; this list may grow over time to comprehend additional roles. The last column in this table provides links to recommended publicly available training courses to help suppliers remediate security skill gaps.
An optional skill assessment tool (quiz) is available, to make it easier for suppliers to identify security skill gaps. There are two versions of the quiz:
- Version to provide to job candidates is available for download here
- Version (with the answers) to assist the supplier in administering the quiz, identifying skill gaps and the remediation plan, is available for download here
It is anticipated that remediation of identified security skill gaps could potentially require several hours of training if the recommended publicly available courses are used. Remediation must be completed no later than the first week after a worker’s assignment to Intel.