unified

UC-TPRM-03 — Bind vendors to security and privacy terms by contract

Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Third-Party / Supply-Chain Risk
type
preventive
category
administrative

Details

unified_id
UC-TPRM-03
title
Bind vendors to security and privacy terms by contract
statement
Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.
domain
Third-Party / Supply-Chain Risk
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    CA-3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SA-4
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-05
    coverage
    full
    relationship
    superset_of
  • framework
    gdpr
    control_id
    GDPR-Art28
    coverage
    full
    relationship
    superset_of
  • framework
    hipaa
    control_id
    HIPAA-164.314
    coverage
    partial
    delta
    group health plan document requirements (164.314(b)) fall outside vendor/BA contracting
    relationship
    intersects_with
  • framework
    ccpa
    control_id
    CCPA-1798.140
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections