{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-08","description":"Define and enforce processes for acquiring, using, managing, and exiting external system services and cloud services in line with the organization's information security requirements. Require external providers to comply with those requirements, define oversight roles and responsibilities on both sides, agree service and exit terms, and monitor provider compliance on an ongoing basis.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SA-9","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.23","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Define and enforce processes for acquiring, using, managing, and exiting external system services and cloud services in line with the organization's information security requirements. Require external providers to comply with those requirements, define oversight roles and responsibilities on both sides, agree service and exit terms, and monitor provider compliance on an ongoing basis.","title":"Govern security of external and cloud service use","unified_id":"UC-TPRM-08"},"id":"uc:UC-TPRM-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-08","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-TPRM-08 — Govern security of external and cloud service use","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:209b66d47c510fe8b8ef374b81a1c27eded3148b3f99b43e513fa02143d80ec1","properties":{},"sourceDetailPath":"/data/v1/records/wf-d32-3114234e.json","sourceId":"wf:D32","targetDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","targetId":"uc:UC-TPRM-08","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7343a8f2d902c6be8f8b8a101f0ecbe48bc9218fb14d40824311bf617cf79997","properties":{},"sourceDetailPath":"/data/v1/records/wf-d55-248b03a5.json","sourceId":"wf:D55","targetDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","targetId":"uc:UC-TPRM-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7ae74228c2b4d9258b2eac2b49ad6e024876640ef5d05f2ecd42f9664a807740","properties":{"rationale":"Requiring external and cloud providers to comply with infosec requirements and monitoring their compliance on an ongoing basis directly counters unmonitored external providers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","sourceId":"uc:UC-TPRM-08","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8a2b869b6565e0c0f8a3c6e50b050c8a06c251b5ab2525441fa18b96ce78b169","properties":{"control_id":"SA-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","sourceId":"uc:UC-TPRM-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-9-0352f849.json","targetId":"ctrl:nist-800-53:SA-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab552cff8ceb7b7872b5b918e5b132763a14652d60fdab55bdb05b5d50840238","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","targetId":"uc:UC-TPRM-08","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b2e15eeb0ac5f83bb68af516e5314a9cb224d33ccdde9514a89d4b0fdb9a8636","properties":{"control_id":"A.5.23","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","sourceId":"uc:UC-TPRM-08","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-23-b73e5b7d.json","targetId":"ctrl:iso-27001:A.5.23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b377a036fbeb12acfa7e1489ea85ed71c46f9f4794f7be2991695249fb37ccbc","properties":{"rationale":"Agreeing service and exit terms and monitoring provider compliance governs external and cloud service delivery, directly addressing non-performance.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","sourceId":"uc:UC-TPRM-08","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfff712ba9169ae990641beb7950363016bd752f94715a49f9b34da88e519aae","properties":{},"sourceDetailPath":"/data/v1/records/wf-g29-6f0c8a46.json","sourceId":"wf:G29","targetDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","targetId":"uc:UC-TPRM-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c180bf11c6883fb71e0998cf0a537c72b2bb6cc5f236fcc7a29c500f4c8a4fc1","properties":{},"sourceDetailPath":"/data/v1/records/wf-d54-eba5e14e.json","sourceId":"wf:D54","targetDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","targetId":"uc:UC-TPRM-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c86031bc4374f6990fb02f9a0ad68d7634a83dea607bcbd4a27e8c6cf4a9db8f","properties":{"rationale":"Governing external and cloud AI service use with agreed exit terms and compliance monitoring reduces AI-provider concentration and outage impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","sourceId":"uc:UC-TPRM-08","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e31a0e5bf9e6f2c306fbf4671ee624e8d4197ae3c7b92b2ade8384ed02f1c586","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","targetId":"uc:UC-TPRM-08","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb33dec0e0cef26005de1cd0c17887708b57d46a4cc76f6d9ab390100dfe48a3","properties":{"rationale":"Agreeing exit terms for external and cloud services reduces lock-in and the impact of a cloud provider's failure or exit.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-08-6de49908.json","sourceId":"uc:UC-TPRM-08","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"}],"schemaVersion":1}
