SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC9.2: CC9.2 Assessing and managing vendor and business partner risk

Risk from vendors and business partners is assessed and managed. Points of focus: engagement requirements cover scope and specification, roles, compliance duties and service levels; risks from vendors, partners and their own vendors are assessed periodically; responsibility for managing them is assigned; communication, resolution and exception-handling protocols are set; vendor and partner performance is assessed and issues are addressed; relationships are ended through defined procedures; in confidentiality engagements, confidentiality commitments consistent with the organisation's own are obtained and compliance checked; and in privacy engagements, privacy commitments are obtained, compliance assessed and corrective action taken. The 2022 revision adds: evaluating vulnerabilities created by vendor and partner relationships, including their access to the organisation's systems and network connections; keeping an inventory of vendors and partners and tiering them; considering threats such as a vendor's financial collapse, its security weaknesses, disruption to its operations, or its inability to satisfy business or regulatory obligations; setting review frequency by each vendor's risk; and ending relationships under procedures set in advance, which can cover getting data back securely and having it deleted from the vendor's systems.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 168 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 16 controls

FedRAMP High · 15 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • PE-17 Alternate Work Site
  • PS-7 External Personnel Security
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-11 Component Authenticity (SR-11)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 15 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • PE-17 Alternate Work Site
  • PS-7 External Personnel Security
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-11 Component Authenticity (SR-11)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

CIS Controls v8 · 11 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.3 Classify Service Providers
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers
  • CIS-15.6 Monitor Service Providers
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-8.12 Collect Service Provider Logs
  • CPS230-37 Service Provider Management Policy
  • CPS230-39 Register of Material Service Providers
  • CPS230-43 Due Diligence Before Entering or Modifying a Material Arrangement
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-50 Formal Agreement Content for Material Arrangements
  • CPS230-P15 Precondition for Reliance on a Service Provider
  • CPS230-P48 Required Content of the Service Provider Management Policy

C5 (Germany) · 6 controls

  • C5-DEV-02 Outsourcing of the development
  • C5-OIS-03 Interfaces and Dependencies
  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties
  • C5-SSO-02 Risk assessment of service providers and suppliers
  • C5-SSO-03 Directory of service providers and suppliers
  • C5-SSO-04 Monitoring of compliance with requirements

ISO 27001:2022 · 6 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 8.30 Outsourced development

ISO 27002:2022 · 6 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 8.30 Outsourced development

ISO 27701:2019 · 6 controls

  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.12.2 Supplier service delivery management
  • 8.5.6 Disclosure of subcontractors used to process PII
  • 8.5.7 Engagement of a subcontractor to process PII
  • 8.5.8 Change of subcontractor to process PII

PCI DSS 4.0 · 6 controls

  • 12.8.1 12.8.1 List of third-party service providers
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective
  • CFTC-SS-29 Recovery Plan Accounts for Essential Service Providers
  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility
  • CFTC-SS-31 Testing Covers Outsourced Resources and Tester Independence from Providers
  • CFTC-SS-5 Systems Development and Quality Assurance Category

HIPAA Security Rule · 5 controls

NIST SP 800-171 Rev 3 · 5 controls

  • 03.12.05 Information Exchange
  • 03.16.03 External System Services
  • 03.17.01 Supply Chain Risk Management Plan
  • 03.17.02 Acquisition Strategies, Tools, and Methods
  • 03.17.03 Supply Chain Requirements and Processes

APRA CPS 234 · 4 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-27 Internal Audit Assessment of Third Party Control Assurance
  • CPS234-P22 Evaluation of Third Party Control Design
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing

DORA · 4 controls

  • DORA-Art.28 ICT third-party risk: general principles
  • DORA-Art.29 Preliminary assessment of ICT concentration risk at entity level
  • DORA-Art.30 Key contractual provisions
  • DORA-Art.31 Designation of critical ICT third-party service providers

NIST SP 800-161 Rev 1 · 4 controls

EU AI Act · 3 controls

ISO 22301:2019 · 3 controls

  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment
  • 8.3.4 Resource requirements
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management
  • ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners
  • MYHR-REG-4 Contracted service provider oversight
  • MYHR-REG-8 Copyright conditions on handling old records for operators and service providers
  • ASBv3-PA-8 Determine access process for cloud provider support
  • DS-2 Ensure software supply chain security

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

NIST SP 800-172 · 2 controls

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 3.11.7e Supply Chain Risk Management Plan

NIST SP 800-218 · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-VENDOR Vendor and Subservice Management

APPI · 1 control

  • SEC03-BP09 Share resources securely with a third party

CMMC 2.0 · 1 control

GDPR · 1 control

ISO/IEC 42001:2023 · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC9.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 168 it maps to, and the evidence behind each claim, over MCP and REST.