{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-03","description":"Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"CA-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SA-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-05","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GDPR-Art28","coverage":"full","framework":"gdpr","relationship":"superset_of"},{"control_id":"HIPAA-164.314","coverage":"partial","delta":"group health plan document requirements (164.314(b)) fall outside vendor/BA contracting","framework":"hipaa","relationship":"intersects_with"},{"control_id":"CCPA-1798.140","coverage":"full","framework":"ccpa","relationship":"superset_of"}],"statement":"Include binding security and privacy requirements in contracts and agreements with vendors, service providers, and processors before access, service delivery, or data exchange begins: required security controls, confidentiality, breach notification, audit rights, subcontractor terms, and data handling, return, and deletion obligations. Document and authorize each information exchange or system interconnection under an appropriate agreement, and review agreements periodically. Ensure agreements satisfy the contractual clause requirements mandated by applicable privacy and security regulations for the data and services involved.","title":"Bind vendors to security and privacy terms by contract","unified_id":"UC-TPRM-03"},"id":"uc:UC-TPRM-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-03","sourceIds":["ccpa","gdpr","hipaa","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-TPRM-03 — Bind vendors to security and privacy terms by contract","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:071946c7f47bc974a5dad8a15a71bae0ed4c9fa115558049369b03248c1b5562","properties":{"control_id":"HIPAA-164.314","coverage":"partial","delta":"group health plan document requirements (164.314(b)) fall outside vendor/BA contracting","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-314-0b44ffa8.json","targetId":"ctrl:hipaa:HIPAA-164.314","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d04968156b772bf7a410f5f378671c49da4e7a97a6afdf67647fdce31650c41","properties":{"rationale":"Ensuring agreements satisfy the contractual clauses mandated by privacy regulations (e.g., GDPR transfer clauses/SCCs) directly enables safeguarded cross-border transfer.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-privacy-cross-border-transfer-8fb379b5.json","targetId":"risk:privacy-cross-border-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:11ba931f331b0ba94293ab12e87aa5f837c7ee771592b41dc6e5ade63b027943","properties":{"rationale":"Contractually defining deliverables and obligations before service begins creates enforceable recourse against non-performance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ea243591d059025cafb390ab8a2a3fbdbea18ae83c420927f942819c083da30","properties":{"control_id":"SA-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-4-b6316937.json","targetId":"ctrl:nist-800-53:SA-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:53a7e11a50d323541c74ab8bc9a41e57728e810b20b91dc44c0eaa12f458c5f1","properties":{"rationale":"Binding required security controls, audit rights, and breach-notification terms into supplier contracts directly supplies the security requirements the risk says are missing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5bb7d70b5ee9e1fbc2e690086bc8c6c87c3981f2956df79404841a49b0f6beb9","properties":{"control_id":"GV.SC-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-05-27e42222.json","targetId":"ctrl:nist-csf-2:GV.SC-05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6db868c65485ee877f1cfd1368a44f6b2f96275089bf0a76de3f35673acc94be","properties":{},"sourceDetailPath":"/data/v1/records/wf-d56-387bb72b.json","sourceId":"wf:D56","targetDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","targetId":"uc:UC-TPRM-03","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fd598b196e61c1753b0491a313d783c4e6647f9346bee365fd94eca69bf0ba5","properties":{"rationale":"Including required security and confidentiality obligations in supplier agreements directly fixes the missing-security-terms facet in supplier contracts.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-hr-missing-security-terms-discipline-0a47163d.json","targetId":"risk:hr-missing-security-terms-discipline","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7a4fcf47042ea9982abc5f27817a6fafef13967f6bdb8024af9b65241982ffb6","properties":{"rationale":"Contractual flow-down of compliance obligations, subcontractor terms, and audit rights creates recourse and deterrence that reduce vicarious-liability exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:978b5a10df7af7edf72444a17627874d24bc8b869a9fe081c28837d9a72329f5","properties":{"control_id":"CA-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-3-99bc8b76.json","targetId":"ctrl:nist-800-53:CA-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b942e1c5dad608655084fe8b0a63671d65b2e2b08497f85ac6f1be23fd85e28a","properties":{"control_id":"GDPR-Art28","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art28-e21fee94.json","targetId":"ctrl:gdpr:GDPR-Art28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c155012acf013e8a1e3c96c8c7765103fb5c190959a137a8a6cc41a1a4350970","properties":{"control_id":"CCPA-1798.140","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-140-775f9cfa.json","targetId":"ctrl:ccpa:CCPA-1798.140","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7087093aa2ac0f2a9cc70fa5acdfb27e33c2c3e142af2d8bfd87f509a2a1c2c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g28-6078329f.json","sourceId":"wf:G28","targetDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","targetId":"uc:UC-TPRM-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe06f755edbc3ac0dc9a18f6201ea633e15a5b502d65b18727d884bce33ddc46","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","targetId":"uc:UC-TPRM-03","type":"oversees"}],"schemaVersion":1}
