unified

UC-TPRM-08 — Govern security of external and cloud service use

Define and enforce processes for acquiring, using, managing, and exiting external system services and cloud services in line with the organization's information security requirements. Require external providers to comply with those requirements, define oversight roles and responsibilities on both sides, agree service and exit terms, and monitor provider compliance on an ongoing basis.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Third-Party / Supply-Chain Risk
type
preventive
category
administrative

Details

unified_id
UC-TPRM-08
title
Govern security of external and cloud service use
statement
Define and enforce processes for acquiring, using, managing, and exiting external system services and cloud services in line with the organization's information security requirements. Require external providers to comply with those requirements, define oversight roles and responsibilities on both sides, agree service and exit terms, and monitor provider compliance on an ongoing basis.
domain
Third-Party / Supply-Chain Risk
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    SA-9
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.5.23
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections