Lloyds MS11.10 Third Party and Outsourcing Cyber Risk - comprehensive third-party risk management programme + PRA SS2/21 Outsourcing and Third Party Risk Management requirements + due diligence at onboarding + cyber security questionnaire (SIG + CAIQ + custom) + right-to-audit clauses + SOC 2 Type II + ISO 27001 + ISO 27701 + certifications + ongoing monitoring + concentration risk analysis (PRA-specific concern for cloud concentration with Amazon Web Services + Microsoft Azure + Google Cloud) + critical third-party identification + critical third party (CTP) designation under FSMA 2023 (UK Financial Services and Markets Act 2023 + PRA/FCA/Bank of England CTP designation regime) + supply chain compromise mitigation (SolarWinds + Kaseya + log4j precedents + 3CX + MOVEit) + Software Bill of Materials (SBOM) + service level agreements (SLA) for security + Subprocessor authorisation + termination + offboarding + data return + deletion + cross-border outsourcing considerations. MS11.14 Cloud Security - cloud workload classification + Lloyds-specific data classification + Public Cloud + Hybrid Cloud + Private Cloud workload placement + shared responsibility model (controller vs provider responsibilities) + Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) alignment + AWS Well-Architected Security Pillar + Azure Security Benchmark + Google Cloud Security Foundations + cloud identity federation + Cloud Access Security Broker (CASB) + Cloud Workload Protection Platform (CWPP) + Cloud-Native Application Protection Platform (CNAPP) + multi-cloud strategy + cloud exit + portability planning + cloud sovereignty (UK data residency requirements under FCA conduct rules). MS11.11 Data Protection and Information Classification - 5-tier classification (Top Secret + Secret + Confidential + Internal + Public) aligned with Lloyds market sensitivity + claims data + premium data + customer PII + reinsurance data + regulator data classifications + Data Loss Prevention (DLP) on endpoints + email + cloud + network + UK GDPR compliance + DPA 2018 + DPO designation + ICO registration + breach notification.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.