TPM-05—Third-Party Contract Requirements
Weight: 10
>Control Description
Mechanisms exist to require contractual requirements for cybersecurity and data protection requirements with third-parties, reflecting the organization's needs to protect its Technology Assets, Applications, Services and/or Data (TAASD).
>Cross-Framework Mappings
PCI DSS v4.0.1
CMMC v2.0
Canada ITSP 10.171
Australia ISM
China Cybersecurity Law
New Zealand HISF
EU DORA
Article 28.1(a)
CompareArticle 29.2
CompareArticle 30.1
CompareArticle 30.2
CompareArticle 30.2(a)
CompareArticle 30.2(b)
CompareArticle 30.2(c)
CompareArticle 30.2(d)
CompareArticle 30.2(e)
CompareArticle 30.2(f)
CompareArticle 30.2(g)
CompareArticle 30.2(h)
CompareArticle 30.2(i)
CompareArticle 30.3
CompareArticle 30.3(a)
CompareArticle 30.3(b)
CompareArticle 30.3(c)
CompareArticle 30.3(d)
CompareArticle 30.3(e)(i)
CompareArticle 30.3(e)(ii)
CompareArticle 30.3(e)(iii)
CompareArticle 30.3(e)(iv)
CompareArticle 30.3(f)(i)
CompareArticle 30.4
CompareSOC 2 TSC (Detailed)
NIST SP 800-171 Rev 3
NIST SP 800-171A Rev 3
NIST AI 600-1
45 CFR 155.260
FBI CJIS
US Data Privacy Framework
CMMC 2.0 Level 1
HIPAA Simplification 2013
§ 164.308(b)(1)
Compare§ 164.308(b)(2)
Compare§ 164.308(b)(3)
Compare§ 164.314(a)(2)(iii)
Compare§ 164.314(b)(1)
Compare§ 164.314(b)(2)(i)
Compare§ 164.314(b)(2)(ii)
Compare§ 164.314(b)(2)(iii)
Compare§ 164.502(a)(4)(i)
Compare§ 164.502(a)(4)(ii)
Compare§ 164.502(e)(1)(i)
Compare§ 164.502(e)(2)
Compare§ 164.504(e)(2)(i)
Compare§ 164.504(e)(2)(i)(A)
Compare§ 164.504(e)(2)(i)(B)
Compare§ 164.504(e)(2)(ii)(J)
Compare§ 164.504(e)(4)(i)(B)(ii)(B)(1)
Compare§ 164.504(e)(4)(i)(B)(ii)(B)(2)
Compare§ 164.504(f)(1)(i)
Compare§ 164.504(f)(2)(i)
Compare§ 164.504(f)(2)(ii)
Compare§ 164.504(f)(2)(ii)(A)
Compare§ 164.504(f)(2)(ii)(B)
Compare§ 164.504(f)(2)(ii)(C)
Compare§ 164.504(f)(2)(ii)(D)
Compare§ 164.504(f)(2)(ii)(E)
Compare§ 164.504(f)(2)(ii)(F)
Compare§ 164.504(f)(2)(ii)(G)
Compare§ 164.504(f)(2)(ii)(H)
Compare§ 164.504(f)(2)(ii)(I)
Compare§ 164.504(f)(2)(ii)(J)
Compare§ 164.504(f)(2)(iii)(A)
Compare§ 164.504(f)(2)(iii)(B)
Compare§ 164.504(f)(2)(iii)(C)
Compare§ 164.504(f)(3)(i)
Compare§ 164.504(f)(3)(ii)
Compare§ 164.504(f)(3)(iii)
Compare§ 164.504(f)(3)(iv)
CompareSEC Cybersecurity Rule
NY DFS 23 NYCRR 500
Oregon CPA
Texas CDPA
Virginia CDPA
Ask AI
Configure your API key to use AI features.