CIS Controls v8
CIS Control 15: Service Provider Management

CIS Controls v8 CIS-15.5: Assess Service Providers

Assess service providers in line with the enterprise service provider management policy. The depth of assessment can depend on classification and may draw on standard assessment reports such as SOC 2 or a PCI Attestation of Compliance (AoC), tailored questionnaires, or other suitably rigorous methods. Reassess each provider at least yearly, and whenever a contract is signed or renewed.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 91 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 10 controls

  • AC-20(1) Limits on Authorized Use
  • CA-2 Control Assessments
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 10 controls

  • AC-20(1) Limits on Authorized Use
  • CA-2 Control Assessments
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

NIST SP 800-53 Rev 5 · 8 controls

  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

ISO 27701:2019 · 6 controls

  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.12.2 Supplier service delivery management
  • 6.15.2 Information security reviews
  • 7.5.4 Records of PII disclosure to third parties
  • 8.5.3 Records of PII disclosure to third parties

ISO 27001:2022 · 5 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services

APRA CPS 234 · 4 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-22 Systematic Control Testing Program
  • CPS234-P22 Evaluation of Third Party Control Design
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing

ISO 27002:2022 · 4 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • ISM-1570 IRAP assessment of cloud providers
  • ISM-1738 Exercising the right to verify compliance
  • ISM-1793 IRAP assessment of managed service providers

ISO 22301:2019 · 3 controls

  • 4.2.2 Legal and regulatory requirements
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment

NIST SP 800-161 Rev 1 · 3 controls

PCI DSS 4.0 · 3 controls

  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • CPS230-43 Due Diligence Before Entering or Modifying a Material Arrangement
  • CPS230-P15 Precondition for Reliance on a Service Provider

DORA · 2 controls

  • DORA-Art.28 ICT third-party risk: general principles
  • DORA-Art.29 Preliminary assessment of ICT concentration risk at entity level

NIST SP 800-171 Rev 3 · 2 controls

  • 03.16.03 External System Services
  • 03.17.03 Supply Chain Requirements and Processes

SOC 2 · 2 controls

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management

APPI · 1 control

  • ASBv3-PA-8 Determine access process for cloud provider support

C5 (Germany) · 1 control

  • C5-SSO-02 Risk assessment of service providers and suppliers
  • CFTC-SS-31 Testing Covers Outsourced Resources and Tester Independence from Providers

CIS Controls v8.1 · 1 control

  • 15.5 Assess Service Providers

HIPAA Security Rule · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

ISO/IEC 42001:2023 · 1 control

  • A.10 Third-party and customer relationships

NIS2 Directive · 1 control

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

NIST SP 800-172 · 1 control

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 15: Service Provider Management

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-15.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.