SOC 2
P - Privacy

SOC 2 P6.4: Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed

Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 198 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 23 controls

  • 5.4 Planning
  • 6.1 General
  • 6.10.2 Information transfer
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.2 Security in development and support processes
  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.12.2 Supplier service delivery management
  • 6.15.1 Compliance with legal and contractual requirements
  • 7.2.6 Contracts with PII processors
  • 7.2.7 Joint PII controller
  • 7.3.7 PII controllers' obligations to inform third parties
  • 7.5 PII sharing, transfer, and disclosure
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 8.2.1 Customer agreement
  • 8.2.5 Customer obligations
  • 8.5 PII sharing, transfer, and disclosure
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.2 Countries and international organizations to which PII can be transferred
  • 8.5.6 Disclosure of subcontractors used to process PII
  • 8.5.7 Engagement of a subcontractor to process PII
  • 8.5.8 Change of subcontractor to process PII

NIST SP 800-53 Rev 5 · 22 controls

  • NIST800-AC-20 Use of external systems
  • NIST800-AC-21 Information Sharing. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information's access and use restrictions for [organization-defined] ; and Employ [organization-defined] to assist users in making information
  • NIST800-AU-16 Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries
  • NIST800-CA-3 Information exchange
  • NIST800-CA-7 Continuous monitoring
  • NIST800-PM-18 Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and the resources
  • NIST800-PM-27 Privacy Reporting. Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; and [organization-defined] and other personnel with responsibility for monitoring privacy program compliance; and Review and update
  • NIST800-PM-9 Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk
  • NIST800-PS-7 External personnel security
  • NIST800-PT-1 Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent
  • NIST800-PT-2 Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-defined] of personally identifiable information to only that which is authorized
  • NIST800-PT-7 Specific Categories of Personally Identifiable Information. Apply [organization-defined] for specific categories of personally identifiable information
  • NIST800-PT-8 Computer Matching Requirements. When a system or organization processes information for the purpose of conducting a matching program: Obtain approval from the Data Integrity Board to conduct the matching program; Develop and enter into
  • NIST800-RA-8 Privacy Impact Assessments. Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes personally identifiable information; and Initiating a new collection of personally identifiable information that:
  • NIST800-SA-4 Acquisition process
  • NIST800-SA-9 External system services
  • NIST800-SR-1 Policy and procedures for supply chain risk management
  • NIST800-SR-3 Supply chain controls and processes
  • NIST800-SR-6 Supplier assessments and reviews
  • NIST800-SR-7 Supply Chain Operations Security. Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: [organization-defined]
  • SP800-53-SA System and Services Acquisition Family
  • SP800-53-SR Supply Chain Risk Management Family

FedRAMP High · 16 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]
  • CA-3 Information Exchange
  • CA-7(1) Independent Assessment
  • PL-8 Security and Privacy Architectures
  • PS-7 External Personnel Security
  • PS-9 Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing
  • SA-9(5) External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 16 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]
  • CA-3 Information Exchange
  • CA-7(1) Independent Assessment
  • PL-8 Security and Privacy Architectures
  • PS-7 External Personnel Security
  • PS-9 Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing
  • SA-9(5) External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-3 Information Exchange
  • CA-7(1) Independent Assessment
  • PL-8 Security and Privacy Architectures
  • PS-7 External Personnel Security
  • PS-9 Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-3 Information Exchange
  • CA-7(1) Independent Assessment
  • PL-8 Security and Privacy Architectures
  • PS-7 External Personnel Security
  • PS-9 Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

ISO 27002:2022 · 10 controls

  • 5.14 Information transfer
  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of PII
  • 6.6 Confidentiality or non-disclosure agreements
  • 8.30 Outsourced development

ISO 27001:2022 · 9 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 6.6 Confidentiality or non-disclosure agreements
  • 8.30 Outsourced development

PCI DSS 4.0 · 9 controls

  • 12.8.1 Third-party service provider inventory
  • 12.8.2 Written agreements with TPSPs
  • 12.8.3 TPSP due diligence
  • 12.8.4 TPSP compliance monitored
  • 12.8.5 Responsibility matrix with TPSPs
  • 12.9.1 TPSP written acknowledgement of responsibility (SP)
  • 12.9.2 TPSP supports customer requests for compliance info (SP)
  • 3.7.9 Service provider customer key responsibilities
  • 8.2.7 Third-party access managed

CIS Controls v8 · 8 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.3 Classify Service Providers
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers
  • CIS-15.6 Monitor Service Providers
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-3.8 Document Data Flows

HIPAA Security Rule · 8 controls

  • AC-20 Use of External Systems
  • CA-3 Information Exchange
  • PS-7 External Personnel Security
  • PS-9 Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)

ISO/IEC 42001:2023 · 7 controls

  • 4.2 Understanding the needs and expectations of interested parties
  • A.10 Third-party and customer relationships
  • A.2.3 Alignment with other organizational policies
  • A.5.4 Assessing AI system impact on individuals or groups
  • A.7.3 Acquisition of data
  • A.8.5 Information for interested parties
  • A.9 Use of AI systems

NIST SP 800-161 Rev 1 · 4 controls

  • MYHR-REG-4 Contracted service provider oversight
  • MYHR-REG-8 Copyright conditions on handling old records for operators and service providers

CCPA/CPRA · 2 controls

  • CCR §7050 Service Provider and Contractor Obligations
  • §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors

DORA · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

APPI · 1 control

APRA CPS 234 · 1 control

  • CPS234-16 Assessment of Related Party and Third Party Capability

C5 (Germany) · 1 control

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties

GDPR · 1 control

ISO 27018 · 1 control

  • A.10.2 Confidentiality obligations of personnel

ISO/IEC 27018:2019 · 1 control

  • A.10.2 Confidentiality obligations of personnel
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 P6.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 198 it maps to, and the evidence behind each claim, over MCP and REST.