Third-Party Risk Management Program
- A third-party risk-management program is maintained under a dedicated policy, with defined roles and processes.
- External system connections are identified, verified, and controlled, and third parties are expected to meet security requirements.
- Vendors handling sensitive data are governed by non-disclosure agreements and security expectations.
Framework Alignment: NIST CSF GV.SC; CIS Control 15; CMMC Level 1 (AC); GDPR Art. 28; ISO 27001:2022 A.5.19, A.5.20, A.5.21