SAMMY works best on screens 1024px wide or larger.
TPM-05.6: Does the organization obtain a First-Party Declaration (1PD) from applicable External Service Providers (ESPs) that provides assurance of compliance with specified statutory, regulatory and contractual obligations for cybersecurity and data privacy controls, including any flow-down requirements to subcontractors?

Mechanisms exist to obtain a First-Party Declaration (1PD) from applicable External Service Providers (ESPs) that provides assurance of compliance with specified statutory, regulatory and contractual obligations for cybersecurity and data privacy controls, including any flow-down requirements to subcontractors.

Description

Mechanisms exist to obtain a First-Party Declaration (1PD) from applicable External Service Providers (ESPs) that provides assurance of compliance with specified statutory, regulatory and contractual obligations for cybersecurity and data privacy controls, including any flow-down requirements to subcontractors.