unified
UC-TPRM-08 — Govern security of external and cloud service use
Define and enforce processes for acquiring, using, managing, and exiting external system services and cloud services in line with the organization's information security requirements. Require external providers to comply with those requirements, define oversight roles and responsibilities on both sides, agree service and exit terms, and monitor provider compliance on an ongoing basis.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-TPRM-08
- title
- Govern security of external and cloud service use
- statement
- Define and enforce processes for acquiring, using, managing, and exiting external system services and cloud services in line with the organization's information security requirements. Require external providers to comply with those requirements, define oversight roles and responsibilities on both sides, agree service and exit terms, and monitor provider compliance on an ongoing basis.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SA-9
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.23
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- GCP Physical and Environmental Subservice Reliance oversees UC-TPRM-08 — Govern security of external and cloud service use
- System and Third-Party Risk Review operates UC-TPRM-08 — Govern security of external and cloud service use
- UC-TPRM-08 — Govern security of external and cloud service use mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Requiring external and cloud providers to comply with infosec requirements and monitoring their compliance on an ongoing basis directly counters unmonitored external providers.
- UC-TPRM-08 — Govern security of external and cloud service use maps_to SA-9 — External System Services
- framework
- nist-800-53
- control_id
- SA-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-08 — Govern security of external and cloud service use
- UC-TPRM-08 — Govern security of external and cloud service use maps_to A.5.23 — Information security for use of cloud services
- framework
- iso-27001
- control_id
- A.5.23
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-08 — Govern security of external and cloud service use mitigates Vendor/outsourcing service non-performance and disputes
- strength
- primary
- rationale
- Agreeing service and exit terms and monitoring provider compliance governs external and cloud service delivery, directly addressing non-performance.
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-08 — Govern security of external and cloud service use
- SOC 2 Reporting and Management Assertion operates UC-TPRM-08 — Govern security of external and cloud service use
- UC-TPRM-08 — Govern security of external and cloud service use mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Governing external and cloud AI service use with agreed exit terms and compliance monitoring reduces AI-provider concentration and outage impact.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-08 — Govern security of external and cloud service use
- UC-TPRM-08 — Govern security of external and cloud service use mitigates Critical vendor failure, insolvency or concentration
- strength
- related
- rationale
- Agreeing exit terms for external and cloud services reduces lock-in and the impact of a cloud provider's failure or exit.