unified

UC-TPRM-04 — Monitor vendor performance, services, and risk

Continuously monitor third-party performance, service delivery, and security posture against contractual and risk requirements throughout the relationship. Conduct periodic reassessments and reviews, such as questionnaires, assurance reports, and audits, at a frequency based on criticality, and manage changes to supplier services. Record, prioritize, and track identified vendor risks through response and remediation.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Third-Party / Supply-Chain Risk
type
detective
category
administrative

Details

unified_id
UC-TPRM-04
title
Monitor vendor performance, services, and risk
statement
Continuously monitor third-party performance, service delivery, and security posture against contractual and risk requirements throughout the relationship. Conduct periodic reassessments and reviews, such as questionnaires, assurance reports, and audits, at a frequency based on criticality, and manage changes to supplier services. Record, prioritize, and track identified vendor risks through response and remediation.
domain
Third-Party / Supply-Chain Risk
control_type
detective
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    SR-6
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-07
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-09
    coverage
    partial
    delta
    integration of practices across the technology life cycle satisfied by program control
    relationship
    intersects_with
  • framework
    iso-27001
    control_id
    A.5.22
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections