GV.OC-03.005
Has your organization implemented a formal process to track and manage cybersecurity requirements in contracts with suppliers, customers, and partners?
Explanation
This question assesses whether your organization has established a systematic approach to identify, document, and monitor cybersecurity obligations specified in contracts with external parties. Such a process ensures that security requirements are clearly defined, communicated, and maintained throughout the relationship lifecycle with third parties who may access, process, or store your sensitive information. Evidence could include a documented procedure for contract management that specifically addresses cybersecurity requirements, a contract management system with cybersecurity tracking capabilities, sample contracts with security clauses, or reports showing regular reviews of third-party compliance with contractual security obligations.
Implementation Example
Determine a process to track and manage contractual requirements for cybersecurity management of supplier, customer, and partner information
ID: GV.OC-03.005
Context
- Function
- GV: GOVERN
- Category
- GV.OC: Organizational Context
- Sub-Category
- Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

