Skip to main content

Repository → 💼 SOC 2 → 💼 CC9 Risk Mitigation → 💼 CC9.2 The entity assesses and manages risks associated with vendors and business partners.

💼 CC9.2-1 Establishes Requirements for Vendor and Business Partner Engagements

  • ID: /frameworks/soc-2/cc9/02/01

Description

The entity establishes specific requirements for a vendor and business partner engagement that includes (1) scope of services and product specifications, (2) roles and responsibilities, (3) compliance requirements, and (4) service levels.

Similar

  • Internal
    • ID: dec-c-cd6b587b

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance