STA-07: Is an inventory of all supply chain relationships developed and maintained?
Both the CSP and CSC should develop, manage and maintain a comprehensive inventory of all supply chain relationships (i.e., third-party product and service providers) involved in implementing, operating, and securing their respective cloud service implementations. This process should include assembling, tracking, and maintaining key organizational roles, contracts, contacts, and risk-related information about each third party in the supply chain regularly (and when significant changes occur) to facilitate supply chain risk management practices.
Control implemented
Control ownership
Description
Develop and maintain an inventory of all supply chain relationships.