Under active development Content is continuously updated and improved

15.5Assess Service Providers

IG3
Users
Govern

>Control Description

Assess service providers consistent with the enterprise’s service provider management policy. Assessment scope may vary based on classification(s), and may include review of standardized assessment reports, such as Service Organization Control 2 (SOC 2) and Payment Card Industry (PCI) Attestation of Compliance (AoC), customized questionnaires, or other appropriately rigorous processes. Reassess service providers annually, at a minimum, or with new and renewed contracts.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.