{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","description":"Because supplier contracts omit security requirements and SLAs and third-party service delivery is not monitored, processors and sub-processors operate without equivalent, audited obligations, so third-party weaknesses and breaches propagate into the organization undetected.","details":{"category":"third_party","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"tprm-weak-supplier-oversight","taxonomies":["iso-27005-vulnerability","nist-privacy-risk"],"treatment":"mitigate"},"id":"risk:tprm-weak-supplier-oversight","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Weak supplier security requirements and monitoring","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:443f786d43ee6948e95374e37c50e83b401cf7827e8bdb8d7420e4abd2529647","properties":{"rationale":"Embedding security requirements and audit/access rights, reviewing service agreements and supplier performance, and reassessing on a cycle directly counters unmonitored, unbound suppliers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:487203ab534ac8c1b60b9ac4aa16278b95af18a66777b5dc85eebdc34019c1b4","properties":{"rationale":"Reviewing and approving data-sharing and matching agreements controls data exposed to third parties.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:53a7e11a50d323541c74ab8bc9a41e57728e810b20b91dc44c0eaa12f458c5f1","properties":{"rationale":"Binding required security controls, audit rights, and breach-notification terms into supplier contracts directly supplies the security requirements the risk says are missing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:747237129db0e2edaa088d008ed4d239673c6ebc02bd80561e44b14183a4b089","properties":{"rationale":"Access revocation and verified data return at termination reduce the residual-access breach vector but supply neither the security requirements nor the ongoing monitoring the risk describes, so the effect is contributory.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","sourceId":"uc:UC-TPRM-06","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7ae74228c2b4d9258b2eac2b49ad6e024876640ef5d05f2ecd42f9664a807740","properties":{"rationale":"Requiring external and cloud providers to comply with infosec requirements and monitoring their compliance on an ongoing basis directly counters unmonitored external providers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","sourceId":"uc:UC-TPRM-08","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a008fa82050e6f042e205aa0944f4bd1c147a25b43a494f895520544af11b5cb","properties":{"rationale":"Supplier incident-notification obligations address the undetected-breach-propagation tail but not the missing-requirements or unmonitored-delivery core, so they contribute to rather than operate the oversight defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b5b6325a613231fc412f5a9686862687f5807b1b487dc76d4cc9c694998a3484","properties":{"rationale":"Pre-engagement security-posture due diligence screens weaker suppliers at selection but does not itself impose contractual security requirements or ongoing monitoring, so it contributes to rather than operating the oversight defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b6cdcd8fe386d6c033b5cf3e139295c50ec3fb0139ce7f5fe959466897e63102","properties":{"rationale":"Identifying, contractually binding, and monitoring subservice orgs via their assurance reports and CUECs directly closes the unmonitored, unbound third-party gap this risk describes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2d3c58671aec19e31faee03ea3ae74ddbe8bca2ab26be3fb48fbdd0a95b8193","properties":{"rationale":"Evaluation criteria for externally developed applications set security requirements on acquired third-party software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f92fde77cb6575136885ea6c52248547e35fb71e3474c0eeb0ef6784819161b4","properties":{"rationale":"Continuously monitoring third-party service delivery and security posture with periodic reassessment is precisely the monitoring the risk says is absent.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"}],"schemaVersion":1}
