CIS Controls v8
CIS Control 15: Service Provider Management

CIS Controls v8 CIS-15.2: Establish and Maintain a Service Provider Management Policy

Set up and keep a policy for managing service providers that deals with how they are classified, inventoried, assessed, monitored and decommissioned. Revisit the policy each year, or sooner when a major change in the enterprise could affect this Safeguard.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 80 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 12.8.1 12.8.1 List of third-party service providers
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

NIST SP 800-53 Rev 5 · 6 controls

FedRAMP High · 5 controls

  • AU-1 Policy and Procedures
  • SA-9 External System Services
  • SR-1 Policy and Procedures (SR-1)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)

FedRAMP Moderate · 5 controls

  • AU-1 Policy and Procedures
  • SA-9 External System Services
  • SR-1 Policy and Procedures (SR-1)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)

HIPAA Security Rule · 5 controls

ISO 27001:2022 · 5 controls

  • 5.1 Policies for information security
  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services

ISO 27701:2019 · 5 controls

  • 5.3.2 Policy
  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.12.2 Supplier service delivery management
  • 6.2.1 Management direction for information security
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained

SOC 2 · 5 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures

NIST SP 800-161 Rev 1 · 3 controls

  • CPS230-37 Service Provider Management Policy
  • CPS230-P48 Required Content of the Service Provider Management Policy

APRA CPS 234 · 2 controls

  • CPS234-19 Information Security Policy Framework
  • CPS234-P19 Policy Direction to All Responsible Parties
  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility
  • CFTC-SS-5 Systems Development and Quality Assurance Category

ISO 27002:2022 · 2 controls

  • 5.19 Information security in supplier relationships
  • 5.21 Managing information security in the ICT supply chain

ISO/IEC 42001:2023 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • 164.316(a) Policies and Procedures (Standard)
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management

APPI · 1 control

  • ISM-1785 Supplier relationship management policy

C5 (Germany) · 1 control

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties

CIS Controls v8.1 · 1 control

  • 15.2 Establish and Maintain a Service Provider Management Policy

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • 03.17.01 Supply Chain Risk Management Plan

NIST SP 800-172 · 1 control

  • 3.11.7e Supply Chain Risk Management Plan

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 15: Service Provider Management

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-15.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 80 it maps to, and the evidence behind each claim, over MCP and REST.