STA-12: Are policies that require all supply chain CSPs to comply with information
security, confidentiality, access control, privacy, audit, personnel policy, and
service level requirements and standards implemented?
Contracts throughout the supply chain should include requirements for all third- and fourth-party service providers and personnel with access to CSP and/or CSC systems and information.
Personnel policies should include employment agreements inclusive of information security requirements, security awareness training, and insider risk management.
Control implemented
Control ownership
Description
Implement policies requiring all CSPs throughout the supply chain
to comply with information security, confidentiality, access control, privacy,
audit, personnel policy and service level requirements and standards.