unified
UC-TPRM-01 — Operate a third-party security risk management program
Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-TPRM-01
- title
- Operate a third-party security risk management program
- statement
- Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SR-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-01
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-02
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-03
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-04
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.19
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.11
- coverage
- partial
- delta
- policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- PM-30
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-17
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21d
- coverage
- partial
- delta
- operational supplier security assessments and contractual safeguards per supplier
- relationship
- intersects_with
- framework
- cobit-2019
- control_id
- APO09
- coverage
- partial
- delta
- service catalog definition and SLA lifecycle management
- relationship
- intersects_with
- framework
- cobit-2019
- control_id
- APO10
- coverage
- partial
- delta
- day-to-day vendor performance monitoring and contract administration
- relationship
- intersects_with
- framework
- dora
- control_id
- DORA-Art28-44
- coverage
- partial
- delta
- DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-01 — Operate a third-party security risk management program maps_to GV.SC-03 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- framework
- nist-csf-2
- control_id
- GV.SC-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-01 — Operate a third-party security risk management program
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-01 — Operate a third-party security risk management program
- UC-TPRM-01 — Operate a third-party security risk management program maps_to GV.SC-01 — Cybersecurity Supply Chain Risk Management: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
- framework
- nist-csf-2
- control_id
- GV.SC-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to PM-30 — Supply Chain Risk Management Strategy
- framework
- nist-800-53
- control_id
- PM-30
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Third-Party ICT Vendor Regulatory Assurance oversees UC-TPRM-01 — Operate a third-party security risk management program
- UC-TPRM-01 — Operate a third-party security risk management program mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Embedding security requirements and audit/access rights, reviewing service agreements and supplier performance, and reassessing on a cycle directly counters unmonitored, unbound suppliers.
- Third-Party Vendor Assurance Engagement tests UC-TPRM-01 — Operate a third-party security risk management program
- UC-TPRM-01 — Operate a third-party security risk management program mitigates Supply-chain disruption of critical inputs
- strength
- related
- rationale
- Assessing concentration and substitutability and maintaining exit strategies reduces the impact of a disrupted critical-input supplier.
- UC-TPRM-01 — Operate a third-party security risk management program mitigates Critical vendor failure, insolvency or concentration
- strength
- primary
- rationale
- Assessing criticality, substitutability, and concentration before contracting and maintaining tested exit strategies for critical providers is the core defense against vendor failure and concentration.
- UC-TPRM-01 — Operate a third-party security risk management program mitigates Geopolitical, macroeconomic and sovereign risk
- strength
- related
- rationale
- Concentration/substitutability assessment and exit strategies reduce the impact of geopolitically-driven supplier and supply-chain disruption.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to GV.SC-02 — Cybersecurity Supply Chain Risk Management: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
- framework
- nist-csf-2
- control_id
- GV.SC-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to A.5.19 — Information security in supplier relationships
- framework
- iso-27001
- control_id
- A.5.19
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to SR-2 — Supply Chain Risk Management Plan
- framework
- nist-800-53
- control_id
- SR-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-01 — Operate a third-party security risk management program
- CSF 2.0 Profile & Maturity Assessment oversees UC-TPRM-01 — Operate a third-party security risk management program
- UC-TPRM-01 — Operate a third-party security risk management program maps_to SR-3 — Supply Chain Controls and Processes
- framework
- nist-800-53
- control_id
- SR-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program mitigates Third-party compliance failure creating vicarious liability
- strength
- related
- rationale
- Risk-based due diligence, a criticality-ranked register, sub-outsourcing conditions, and reassessment reduce the N-tier compliance-failure exposure driving vicarious liability.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to APO10 — Managed Vendors
- framework
- cobit-2019
- control_id
- APO10
- coverage
- partial
- delta
- day-to-day vendor performance monitoring and contract administration
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to SR-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- SR-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to 500.11 — Third-party service provider security policy
- framework
- nydfs-500
- control_id
- 500.11
- coverage
- partial
- delta
- policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program mitigates Vendor/outsourcing service non-performance and disputes
- strength
- primary
- rationale
- Defining, agreeing, and reviewing service agreements and supplier performance and operating lifecycle controls to address weaknesses directly targets non-performance.
- UC-TPRM-01 — Operate a third-party security risk management program mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- A criticality-ranked third-party register plus concentration and exit-strategy assessment applies to AI API providers, reducing concentration and outage impact.
- UC-TPRM-01 — Operate a third-party security risk management program mitigates GPAI transparency, systemic-risk and synthetic-content obligations
- strength
- related
- rationale
- Assessing concentration risk and maintaining exit strategies for critical providers reduces the ecosystem single-point-of-failure impact from GPAI-capability concentration.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to PM-17 — Protecting Controlled Unclassified Information on External Systems
- framework
- nist-800-53
- control_id
- PM-17
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to DORA-Art28-44 — Managing of ICT third-party risk
- framework
- dora
- control_id
- DORA-Art28-44
- coverage
- partial
- delta
- DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program
- relationship
- intersects_with
- source_version
- Regulation (EU) 2022/2554
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to NIS2-Art21d — Supply chain security
- framework
- nis2
- control_id
- NIS2-Art21d
- coverage
- partial
- delta
- operational supplier security assessments and contractual safeguards per supplier
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to APO09 — Managed Service Agreements
- framework
- cobit-2019
- control_id
- APO09
- coverage
- partial
- delta
- service catalog definition and SLA lifecycle management
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-01 — Operate a third-party security risk management program maps_to GV.SC-04 — Cybersecurity Supply Chain Risk Management: Suppliers are known and prioritized by criticality
- framework
- nist-csf-2
- control_id
- GV.SC-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.