unified
UC-TPRM-03 — Bind vendors to security and privacy terms by contract
Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-TPRM-03
- title
- Bind vendors to security and privacy terms by contract
- statement
- Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CA-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SA-4
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-05
- coverage
- full
- relationship
- superset_of
- framework
- gdpr
- control_id
- GDPR-Art28
- coverage
- full
- relationship
- superset_of
- framework
- hipaa
- control_id
- HIPAA-164.314
- coverage
- partial
- delta
- group health plan document requirements (164.314(b)) fall outside vendor/BA contracting
- relationship
- intersects_with
- framework
- ccpa
- control_id
- CCPA-1798.140
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract maps_to HIPAA-164.314 — Organizational requirements (business associate contracts, group health plan requirements)
- framework
- hipaa
- control_id
- HIPAA-164.314
- coverage
- partial
- delta
- group health plan document requirements (164.314(b)) fall outside vendor/BA contracting
- relationship
- intersects_with
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract mitigates Cross-border personal-data transfer without safeguards
- strength
- primary
- rationale
- Ensuring agreements satisfy the contractual clauses mandated by privacy regulations (e.g., GDPR transfer clauses/SCCs) directly enables safeguarded cross-border transfer.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract mitigates Vendor/outsourcing service non-performance and disputes
- strength
- related
- rationale
- Contractually defining deliverables and obligations before service begins creates enforceable recourse against non-performance.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract maps_to SA-4 — Acquisition Process
- framework
- nist-800-53
- control_id
- SA-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Binding required security controls, audit rights, and breach-notification terms into supplier contracts directly supplies the security requirements the risk says are missing.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract maps_to GV.SC-05 — Cybersecurity Supply Chain Risk Management: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
- framework
- nist-csf-2
- control_id
- GV.SC-05
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Vendor Risk Assessment and Disposition oversees UC-TPRM-03 — Bind vendors to security and privacy terms by contract
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract mitigates Missing security terms in contracts and no disciplinary process
- strength
- primary
- rationale
- Including required security and confidentiality obligations in supplier agreements directly fixes the missing-security-terms facet in supplier contracts.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract mitigates Third-party compliance failure creating vicarious liability
- strength
- related
- rationale
- Contractual flow-down of compliance obligations, subcontractor terms, and audit rights creates recourse and deterrence that reduce vicarious-liability exposure.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract maps_to CA-3 — Information Exchange
- framework
- nist-800-53
- control_id
- CA-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract maps_to GDPR-Art28 — Processor obligations and data processing agreements
- framework
- gdpr
- control_id
- GDPR-Art28
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Regulation (EU) 2016/679
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract maps_to CCPA-1798.140 — Service-provider and contractor contract requirements
- framework
- ccpa
- control_id
- CCPA-1798.140
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- CCPA (2018) as amended by CPRA (2020)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Vendor Due Diligence & Contracting Gate operates UC-TPRM-03 — Bind vendors to security and privacy terms by contract
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-03 — Bind vendors to security and privacy terms by contract