Logo

CISOBot - Your AI CISO Assistant

CLD-13

Hosted Assets, Applications & Services

Weight: 9/10
Description

Mechanisms exist to specify applicable cybersecurity and data protection controls that must be implemented on external Technology Assets, Applications and/or Services (TAAS), consistent with the contractual obligations established with the External Service Providers (ESP) owning, operating and/or maintaining external TAAS.

Control Question

Does the organization specify applicable cybersecurity and data protection controls that must be implemented on external Technology Assets, Applications and/or Services (TAAS), consistent with the contractual obligations established with the External Service Providers (ESP) owning, operating and/or maintaining external TAAS?

Control Metadata
Domain:

Cloud Security

Validation Cadence:

Annual

Have questions about this control?

Ask CISOBot for implementation guidance and best practices