Terms of service
Service description for BlueVoyant Third-Party Risk Management – Questionnaire Managed Service – Auto-ISAC TRACK Program for Suppliers
(SKU: TPRM-QAR-QMS-ATPS)
This document (the “Service Description”) describes the BlueVoyant Third-Party Risk Management Auto-ISAC TRACK Program (the “Service”) that BlueVoyant will provide to Suppliers (the “Client”), of Auto-ISAC’s Original Equipment Manufacturer (“OEM”) members named in a signed service order, quote, or web order between the Client and BlueVoyant, a BlueVoyant affiliate, or an authorized BlueVoyant reseller (the “Order”). The Service is provided pursuant to the BlueVoyant Standard Terms and Conditions available at https://www.bluevoyant.com/bvmsa, (the “Standard Terms”) or, if the Services were purchased from an authorized BlueVoyant reseller, and the terms of the purchase agreement between Client and the reseller expressly supersede the Standard Terms, the terms agreed between the reseller and the Client shall prevail, in each case to the exclusion of all other terms.
The specific quantity of Service purchased, term of Service, and associated billing frequency will be set forth in the Order. The Service, as well as all communications, data sets, security detection content, and documents relating to the Service shall be in English. If any part of this Service Description or the Service is translated into any language other than English, the English language version shall prevail.
1. Overview
The Service provides a comprehensive cybersecurity assessment program for Client to meet the requirements established by Auto-ISAC and its member OEMs. The Service is delivered utilizing the Questionnaire Management Platform (“Platform”), which allows the Client to provide responses to the Auto-ISAC TRACK cybersecurity assessment and share results of the assessment with Auto-ISAC's participating member OEMs. The Platform will allow the Client to extract and generate answers from their documents (policies, reports, etc.) with exceptional accuracy and maintain an answer library that can be used to prepopulate answers. The Platform will also provide a centralized solution for the Client to retain and share their assessment results with participating OEMs eliminating the need for multiple, overlapping assessments.
Upon initiation by Client, BlueVoyant’s dedicated Questionnaire Risk Operation Center (“QROC”) team will send an assessment to Client through the Platform. The Client must provide answers to the assessment questions along with supporting evidence within specified timelines. After receiving the responses and documentation, the QROC team will review them, assign an assessment score, and identify any gaps or missing controls. The QROC team will share these reported issues with the Client and work on remediation within a defined timeline. . Once the assessment is complete and Client’s score is finalized, the Client can generate a report and share it with the OEMs. The Client can retain the assessment and all associated metadata in the Platform for 24 months, during which they can share the assessment and its results with one or multiple OEMs at any time.
2. Service Elements
2.1 Service Kickoff: The Auto-ISAC third-party enterprise cybersecurity working group established the framework and processes for supplier assessments and defined a standardized cybersecurity questionnaire titled “TRACK” designed to evaluate and enhance cyber resilience across the automotive supply chain driven by a common library of cybersecurity controls. The Client assessment is initiated by the QROC team. This phase involves confirming Client organizational details and points of contact within Client organization. Deliverables resulting from the overall program preparedness include:
(a) Onboarding Survey with Client Responses.
(b) Third Party Risk Management (“TPRM”) Auto-ISAC TRACK Program process flow for Service, which includes documentation related to the assessment and issue management steps and process details.
2.2 Questionnaire Onboarding: Pre-built standard BlueVoyant questionnaire templates, or any custom questionnaire templates adopted and digitized from Auto-ISAC, will be readily available within the Platform for the assessment. Client will be assessed using these pre-approved and digitized questionnaires.
2.3 Questionnaire Distribution and Response Collection: Once the onboarding has been completed, the QROC team will distribute the assessment questionnaires. Client’s active participation in providing timely and accurate responses and supporting evidence is crucial. This process consists of:
(a) Establishing assessment schedule including due dates and tracking of assessment progress.
(b) Sending questionnaires to Client.
(c) Solicitation and review of Client responses and supporting evidence within the Platform.
(d) Comparison of responses with prior answers, if available from previous assessments.
(e) Outreach (within the Platform), for clarifications to responses, evidence or comments provided as part of assessment questionnaire.
2.4 Issues Identification: The QROC team will perform the following support activities related to the assessment:
(a) Identification of issues within Client environment through the evaluation of questionnaire responses and/or supporting evidence.
(b) Engagement with Client contacts through the Platform to document risk treatment activities.
(c) Documentation of remediation timelines with Client organization.
(d) Tracking of issue status and Client planned remediation approach (e.g., remediation, risk avoidance, temporary exception, acceptance or mitigation).
(e) Analysis of corrective actions performed by Client organization to determine if the identified control gap has been resolved.
(f) Transition of Unresolved Issues: If issues are not closed by Client, within the defined timelines, the QROC team will transition those issues to the Client for ownership and further action.
2.5 Remediation Support: Remediation support requires Client’s active participation to evaluate the validity of the issues identified and subsequently provide a response plan and timeline for corrective actions. The QROC will evaluate the remediation activities taken by Client to determine if it satisfies the required control requirements. As detailed in section 2.4, issues not closed by Client’s organization within specified timelines will be transitioned to Client for ownership.
2.6 Assessment Report Sharing: Upon completion of Client assessment and finalization of score, Client will be able to generate a report from the Platform and share it with one or multiple Auto-ISAC member OEMs. Client can maintain access to the assessment and its metadata on the Platform for up to 24 months, enabling them to share the results with one or multiple OEMs at any point during this timeframe.
3. Service Delivery Teams
3.1 The Service Delivery Team: The Service Delivery Team is composed of the following:
(a) Client Success Manager (CSM): The CSM serves as the primary point of contact for Auto-ISAC to facilitate overall program coordination. Your direct point of contact for assessment queries will primarily be the QROC team. The CSM will be the primary point of contact responsible for facilitating and addressing any platform access related Client requests.
(b) Questionnaire Risk Operations Center (QROC): The QROC is a team of highly qualified cyber risk analysts responsible for the assessment, analysis, tracking, and escalation of issues that are discovered as part of your assessment. The QROC will interact with Client through the questionnaire platform during the assessment process.
(c) Deployment Team: BlueVoyant’s Deployment Team (“onboarding team”) is responsible for platform set-up, user account provisioning, and other activities required to ensure the questionnaire platform is ready for the Client’s use.
4. Service Activation
Service activation for Client’s cybersecurity assessment will formally begin once registration has been successfully processed. Subsequently, BlueVoyant's onboarding team will set up Client’s environment within the Platform, ensuring all required access and configurations are in place. Once the environment setup is complete, the QROC team will publish the assessment in the Platform. Client’s active engagement and timely participation are crucial for a timely process, involving the provision of accurate and complete responses to the assigned questionnaire and all requested supporting documentation and evidence. The timeline for sending out questionnaires, receiving completed responses, and processing submission will be jointly managed with the QROC team to ensure efficient progression.
5. Service Level Agreements and Maintenance
(a) Platform Availability: BlueVoyant targets a service availability of 99.5% of the Platform, excluding scheduled maintenance and updates.
(b) Scheduled Maintenance Windows: Scheduled maintenance is performed biweekly on Friday’s 6:30 PM to 10:30 PM Eastern. SLAs shall not apply during maintenance outages.
(c) Emergency Maintenance: When immediate changes are required, BlueVoyant may initiate an emergency maintenance window. When this situation occurs, BlueVoyant will use commercially reasonable efforts to provide notice and minimize the impact to the Client.
6. Communication & Client Engagement
6.1 Methods of Communication: Below are the standard methods for Client to obtain information related to the Service or engage BlueVoyant staff:
(a) BlueVoyant Implementation and Onboarding Team: The implementation and onboarding team is responsible for Service set-up, user account provisioning and other activities required to ensure the Service is provisioned for Client use.
(b) Platform: The BlueVoyant Platform is the primary method by which Clients can stay informed of activities of the Service. At any time, a Client can go to the Platform and review the latest updates on their assessment program and see all actions taken by the QROC Team.
(c) Email: The Client will receive emails as a regular function of the Service. Email topics can vary, including updates/reminders related to on-boarding activities and assessment updates. Client can also initiate service change requests via email at: tprm_qms@bluevoyant.com.
7. Client Responsibilities
7.1 Client Responsibilities: The following Client responsibilities apply for successful provision of the Services by BlueVoyant:
(a) Active Engagement: Client is responsible for actively engaging in the assessment process by providing accurate and complete responses to the questionnaire, along with all required evidence, within the defined timelines.
(b) Content License: Client is responsible for materials, information or content (the “Content”) Client submits as part of the Service. Submitting Content that facilitates or encourages a violation of any law or regulation by others; impersonates or invades the privacy of another; infringes the rights of any third-party, including intellectual property, business, contractual and fiduciary rights; or other illegal activities; or interferes with the functioning of the Service is prohibited. BlueVoyant does not screen, edit, or monitor Content and takes no responsibility and assumes no liability for it. Client may not use the Service to store or transmit any information that contains or is used to initiate a denial-of-service attack, software viruses or other harmful or deleterious computer code, files or programs such as Trojan horses, worms, time bombs, or spyware.
(c) Content Use: Client grants BlueVoyant the right to use, copy, transmit, reproduce, modify, store, display and disclose Content solely as and to the extent needed for the following purposes: (i) to enable Client’s users’ access to and use of the Platform; (ii) to collect website engagement information in aggregated anonymized form for the sole purpose of improving its services (such information shall not contain any personally identifiable data); or, (iii) after notifying Client and reasonably cooperating with Client to limit related disclosures (except where prohibited by applicable law), to comply with any request of a governmental or regulatory body (including subpoenas or court orders), or as otherwise required by law.
(d) Unauthorized Use: Client must notify BlueVoyant promptly in writing when Client suspects or becomes aware of any unauthorized use of an end users account, the platform or content, including if there has been any loss, theft or other security breach of its users’ passwords or user IDs.
8. Service Boundaries
8.1 Assessment Limits: The Service is comprised of one comprehensive assessment of Client’s organization, ensuring dedicated oversight and control for Client’s cybersecurity assessment required by Auto-ISAC OEMs. Please note that the publication of additional assessments to Client through the Platform is not supported under this license.
8.2 Service Escalations: If questionnaire responses or required clarifications are dormant or assigned to unresponsive individuals within Client’s organization, they will be flagged and referred back or escalated as non-responsive to the Client.
8.3 Issue Management and Scope: The QROC team will manage issues identified specifically as a result of Client’s responses to the assessment distributed by QROC. The QROC team will not be responsible for managing any issues that fall outside the scope of this specific assessment. Issues identified during Client’s assessment will undergo risk treatment which could include remediation, avoidance, temporary exception, transfer, or acceptance of the risk.
(a) Risk Treatment Alignment: For issues within the defined scope of your assessment, risk treatment will follow the recommendations specified at the issue level. All issues will be documented in the Platform and shared with Client. Each issue record has an issue recommendation linked to it which Client will have access to in the Platform. These recommendations will be in alignment with industry standard practices and supported by evidence provided by Client assessment.
(b) Exclusions: Any issues not arising from Client responses to the Auto-ISAC OEM cybersecurity assessment distributed by the BlueVoyant managed service team are excluded from the QROC team's management responsibilities.
8.4 Service Modifications: Adjustments to the questionnaires used in the Auto-ISAC program, should they occur, will adhere to a defined change management process and implementation schedule occurring no more frequently than six (6) month increments.
9. Out of Scope Items
9.1 Out of Scope: The following services are considered out of scope for the Service:
(a) Access, setup, or use of any Client information technology systems, including email, to support any processes or workflows outside of the Service platform.
(b) Ad hoc meetings or direct engagement with Client’s organization beyond the standard Platform assessment workflow and questionnaire clarifications.
(c) Any assessment scope or additional due diligence activities that extend beyond the Auto-ISAC TRACK program.
(d) Engaging or communicating with Client outside of the Platform to perform assessments or gather necessary clarifications falls outside the scope of the service.
(e) Any other services or solutions outside of those explicitly included in this Service Description.
10. Additional Matters
10.1 Questionnaire Platform: The Service leverages the Platform and requires Client to have an active license to the Platform which is part of the service.
10.2 Data Requests: Client will have thirty (30) days from the time a cancellation request is initiated, or the agreement is terminated (whichever comes first) to request a copy of any service specific data you would like BlueVoyant to provide.