SOC 2
P - Privacy

SOC 2 SOC2-P6.4: P6.4 Privacy commitments from vendors and third parties

Privacy commitments are obtained from vendors and others outside the organisation that can reach personal information, their compliance is assessed periodically and as needed, and corrective action is taken where necessary. Points of focus: information goes only to third parties with agreements to protect it consistently with the notice, whose controls are evaluated; and misuse by a third party that received information triggers remedial action. As revised in 2022, the organisation also has procedures to evaluate whether third parties meet their privacy commitments.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 164 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 23 controls

  • 5.4 Planning
  • 6.1 General
  • 6.10.2 Information transfer
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.2 Security in development and support processes
  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.12.2 Supplier service delivery management
  • 6.15.1 Compliance with legal and contractual requirements
  • 7.2.6 Contracts with PII processors
  • 7.2.7 Joint PII controller
  • 7.3.7 PII controllers' obligations to inform third parties
  • 7.5 PII sharing, transfer, and disclosure
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 8.2.1 Customer agreement
  • 8.2.5 Customer obligations
  • 8.5 PII sharing, transfer, and disclosure
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.2 Countries and international organizations to which PII can be transferred
  • 8.5.6 Disclosure of subcontractors used to process PII
  • 8.5.7 Engagement of a subcontractor to process PII
  • 8.5.8 Change of subcontractor to process PII

NIST SP 800-53 Rev 5 · 22 controls

FedRAMP High · 16 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CA-3 Information Exchange
  • CA-7(1) Independent Assessment
  • PL-8 Security and Privacy Architectures
  • PS-7 External Personnel Security
  • PS-9 Position Descriptions (PS-9)
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 16 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CA-3 Information Exchange
  • CA-7(1) Independent Assessment
  • PL-8 Security and Privacy Architectures
  • PS-7 External Personnel Security
  • PS-9 Position Descriptions (PS-9)
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

ISO 27002:2022 · 10 controls

  • 5.14 Information transfer
  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of PII
  • 6.6 Confidentiality or non-disclosure agreements
  • 8.30 Outsourced development

ISO 27001:2022 · 9 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 6.6 Confidentiality or non-disclosure agreements
  • 8.30 Outsourced development

PCI DSS 4.0 · 9 controls

  • 12.8.1 12.8.1 List of third-party service providers
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 12.9.1 12.9.1 TPSP written acknowledgments to customers
  • 12.9.2 12.9.2 TPSP support for customer information requests
  • 3.7.9 3.7.9 Key guidance for service provider customers
  • 8.2.7 8.2.7 Third-party remote access accounts controlled

CIS Controls v8 · 8 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.3 Classify Service Providers
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers
  • CIS-15.6 Monitor Service Providers
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-3.8 Document Data Flows

HIPAA Security Rule · 8 controls

ISO/IEC 42001:2023 · 7 controls

  • 4.2 Understanding the needs and expectations of interested parties
  • A.10 Third-party and customer relationships
  • A.2.3 Alignment with other organizational policies
  • A.5.4 Assessing AI system impact on individuals or groups of individuals
  • A.7.3 Acquisition of data
  • A.8.5 Information for interested parties
  • A.9 Use of AI systems

NIST SP 800-161 Rev 1 · 4 controls

  • MYHR-REG-4 Contracted service provider oversight
  • MYHR-REG-8 Copyright conditions on handling old records for operators and service providers

CCPA/CPRA · 2 controls

  • CCR §7050 Service Provider and Contractor Obligations
  • §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors

DORA · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

APPI · 1 control

APRA CPS 234 · 1 control

  • CPS234-16 Assessment of Related Party and Third Party Capability

C5 (Germany) · 1 control

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties

GDPR · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-P6.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 164 it maps to, and the evidence behind each claim, over MCP and REST.