Under active development Content is continuously updated and improved

Article 28.5Article 28.5

>Control Description

Financial entities may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards. When those contractual arrangements concern critical or important functions, financial entities shall, prior to concluding the arrangements, take due consideration of the use, by ICT third- party service providers, of the most up-to-date and highest quality information security standards.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.