Skip to main content

๐Ÿ’ผ CC9.2 The entity assesses and manages risks associated with vendors and business partners.

  • Contextual name: ๐Ÿ’ผ CC9.2 The entity assesses and manages risks associated with vendors and business partners.

  • ID: /frameworks/soc-2/cc9/02

  • Located in: ๐Ÿ’ผ CC9 Risk Mitigation

Descriptionโ€‹

Empty...

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ CC9.2-1 Establishes Requirements for Vendor and Business Partner Engagements
๐Ÿ’ผ CC9.2-2 Identifies Vulnerabilities
๐Ÿ’ผ CC9.2-3 Assesses Vendor and Business Partner Risks
๐Ÿ’ผ CC9.2-4 Assigns Responsibility and Accountability for Managing Vendors and Business Partners
๐Ÿ’ผ CC9.2-5 Establishes Communication Protocols for Vendors and Business Partners
๐Ÿ’ผ CC9.2-6 Establishes Exception Handling Procedures From Vendors and Business Partners
๐Ÿ’ผ CC9.2-7 Assesses Vendor and Business Partner Performance
๐Ÿ’ผ CC9.2-8 Implements Procedures for Addressing Issues Identified During Vendor and Business Partner Assessments
๐Ÿ’ผ CC9.2-9 Implements Procedures for Terminating Vendor and Business Partner Relationships
๐Ÿ’ผ CC9.2-10 Obtains Confidentiality Commitments from Vendors and Business Partners
๐Ÿ’ผ CC9.2-11 Assesses Compliance With Confidentiality Commitments of Vendors and Business Partners
๐Ÿ’ผ CC9.2-12 Obtains Privacy Commitments from Vendors and Business Partners
๐Ÿ’ผ CC9.2-13 Assesses Compliance with Privacy Commitments of Vendors and Business Partners