SOC 2
P - Privacy

SOC 2 SOC2-P6.5: P6.5 Vendor commitments to report unauthorised disclosures

Outside parties, vendors included, that can reach personal information commit to notify the organisation of actual or suspected unauthorised disclosures; notifications reach the right people and are handled under incident response procedures. Points of focus: remedial action follows misuse by a third party; and a process obtains commitments from vendors to report actual or suspected unauthorised disclosures.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 88 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 17 controls

  • 6.1 General
  • 6.10.2 Information transfer
  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.12.2 Supplier service delivery management
  • 6.15.1 Compliance with legal and contractual requirements
  • 7.2.6 Contracts with PII processors
  • 7.2.7 Joint PII controller
  • 7.3.7 PII controllers' obligations to inform third parties
  • 7.5 PII sharing, transfer, and disclosure
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 8.5 PII sharing, transfer, and disclosure
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.5 Legally binding PII disclosures
  • 8.5.7 Engagement of a subcontractor to process PII
  • 8.5.8 Change of subcontractor to process PII

NIST SP 800-53 Rev 5 · 11 controls

  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

HIPAA Security Rule · 8 controls

FedRAMP High · 7 controls

  • AC-20 Use of External Systems
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • PS-7 External Personnel Security
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-8 Notification Agreements (SR-8)

FedRAMP Moderate · 7 controls

  • AC-20 Use of External Systems
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • PS-7 External Personnel Security
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-8 Notification Agreements (SR-8)

ISO 27001:2022 · 3 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain

ISO 27002:2022 · 3 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain

CIS Controls v8 · 2 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements

GDPR · 2 controls

ISO/IEC 42001:2023 · 2 controls

  • A.10 Third-party and customer relationships
  • A.8.3 External reporting

NIST SP 800-161 Rev 1 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.9.1 12.9.1 TPSP written acknowledgments to customers

C5 (Germany) · 1 control

  • C5-SSO-04 Monitoring of compliance with requirements

CCPA/CPRA · 1 control

  • §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors

CMMC 2.0 · 1 control

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-P6.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.