Authorised Economic Operator (AEO) Programmes - Global Standards
AEO Conditions and Requirements (SAFE Annex IV)

Authorised Economic Operator (AEO) Programmes - Global Standards AEO-7: Trading Partner Security

The operator encourages contracting parties to assess and enhance their supply chain security, including such requirements in contractual arrangements where practical for its business model.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 21 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

CIS Controls v8 · 2 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements

ISO 27001:2022 · 2 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements

ISO 27002:2022 · 2 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements

NIST SP 800-53 Rev 5 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • DS-2 Ensure software supply chain security

FedRAMP High · 1 control

  • SR-3 Supply Chain Controls and Processes (SR-3)

FedRAMP Moderate · 1 control

  • SR-3 Supply Chain Controls and Processes (SR-3)

HIPAA Security Rule · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • 03.17.03 Supply Chain Requirements and Processes
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

SOC 2 · 1 control

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AEO Conditions and Requirements (SAFE Annex IV)

Query this from an agent

The graph holds this control, the 21 it maps to, and the evidence behind each claim, over MCP and REST.