STA-02: Is the SSRM applied, documented, implemented, and managed throughout the supply
chain for the cloud service offering?
The SSRM must explicitly detail each specific service based on the cloud service model and implementation specifics. Accordingly, each party in the supply chain must document, implement and manage their SSRM responsibilities for their specific service. This includes supporting service providers such as infrastructure as a service (IaaS) providers engaged by primary software as a service (SaaS) CSPs and specialized CSPs (e.g., IDaaS, CASB, DDOS/CDN/DNS services) employed by the CSP and/or the CSC.
Control implemented
Control ownership
Description
Apply, document, implement and manage the SSRM throughout the supply
chain for the cloud service offering.