STA-08: Are risk factors associated with all organizations within the supply chain
periodically reviewed by CSPs?
Both the CSP and CSC should follow applicable local and international third-party risk management (TPRM) best practices in managing supply chain risks, including periodic reviews of organizational and technical risk factors, contract requirements, environmental changes, and security incident response capabilities for all supply chain organizations. There may also be applicable regulatory requirements and standards to consider.
Control implemented
Control ownership
Description
CSPs periodically review risk factors associated with all organizations
within their supply chain.