SOC 2 SOC2-CC9.2: CC9.2 Assessing and managing vendor and business partner risk
Risk from vendors and business partners is assessed and managed. Points of focus: engagement requirements cover scope and specification, roles, compliance duties and service levels; risks from vendors, partners and their own vendors are assessed periodically; responsibility for managing them is assigned; communication, resolution and exception-handling protocols are set; vendor and partner performance is assessed and issues are addressed; relationships are ended through defined procedures; in confidentiality engagements, confidentiality commitments consistent with the organisation's own are obtained and compliance checked; and in privacy engagements, privacy commitments are obtained, compliance assessed and corrective action taken. The 2022 revision adds: evaluating vulnerabilities created by vendor and partner relationships, including their access to the organisation's systems and network connections; keeping an inventory of vendors and partners and tiering them; considering threats such as a vendor's financial collapse, its security weaknesses, disruption to its operations, or its inability to satisfy business or regulatory obligations; setting review frequency by each vendor's risk; and ending relationships under procedures set in advance, which can cover getting data back securely and having it deleted from the vendor's systems.
This control maps to 168 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
You are reading one control. How much of SOC 2 have you already done?
SOC 2 SOC2-CC9.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.