Suppliers and other third parties periodically attest to their ability to meet cybersecurity requirements
Agreements with suppliers and other third parties should require attestation that they meet cybersecurity requirements detailed in the agreement terms. Suppliers and third parties should initially attest to meeting these requirements before execution of the agreement, along with periodically attesting that they still meet the cybersecurity requirements. For key suppliers, additional validation of attestations may be considered. This may be performed through monitoring for incidents of note, information from third party rating services, and open-source information.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: THIRD-PARTIES-2c, THIRD-PARTIES-2f, THIRD-PARTIES-2g, THIRD-PARTIES-2h.