15.2: Establish and Maintain a Service Provider Management Policy

CSF v1.1 References:

CSF v2.0 References:

PF v1.0 References:


Info icon.

Control is new to this version of the control set.

Control Statement

Establish and maintain a service provider management policy. Ensure the policy addresses the classification, inventory, assessment, monitoring, and decommissioning of service providers. Review and update the policy annually, or when significant enterprise changes occur that could impact this Safeguard.

[csf.tools Note: For more information on the Critical Security Controls, visit the Center for Internet Security.]