graphgrc

SCF - TPM-10 - Managing Changes To Third-Party Services

Mechanisms exist to control changes to services by suppliers, taking into account the criticality of business information, systems and processes that are in scope by the third-party.

Mapped framework controls

ISO 27002

NIST 800-53

SOC 2

Control questions

Does the organization control changes to services by suppliers, taking into account the criticality of business information, systems and processes that are in scope by the third-party?