The organization shall establish and enforce security requirements for business-critical third-party providers and users.
Third-party providers shall be required to notify any personnel transfers, termination, or transition involving personnel with physical or logical access to organization's business critical system's components.
The organization shall monitor business critical service providers and users for security compliance.
The organization shall audit business-critical external service providers for security compliance.