unified

UC-TPRM-01 — Operate a third-party security risk management program

Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Third-Party / Supply-Chain Risk
type
preventive
category
administrative

Details

unified_id
UC-TPRM-01
title
Operate a third-party security risk management program
statement
Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.
domain
Third-Party / Supply-Chain Risk
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    SR-2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SR-3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-01
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-02
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-03
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-04
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.5.19
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.11
    coverage
    partial
    delta
    policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines
    relationship
    intersects_with
  • framework
    nist-800-53
    control_id
    PM-30
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SR-1
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    PM-17
    coverage
    full
    relationship
    superset_of
  • framework
    nis2
    control_id
    NIS2-Art21d
    coverage
    partial
    delta
    operational supplier security assessments and contractual safeguards per supplier
    relationship
    intersects_with
  • framework
    cobit-2019
    control_id
    APO09
    coverage
    partial
    delta
    service catalog definition and SLA lifecycle management
    relationship
    intersects_with
  • framework
    cobit-2019
    control_id
    APO10
    coverage
    partial
    delta
    day-to-day vendor performance monitoring and contract administration
    relationship
    intersects_with
  • framework
    dora
    control_id
    DORA-Art28-44
    coverage
    partial
    delta
    DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections