Security Questionnaire Mapper
Question group

Third parties and subprocessors

The supplier's own suppliers: who else touches the customer's data, whether the customer is told before that changes, and how those suppliers are assessed.

The families

2 families
Family and a typical questionISO 27001Evidence expected
Subcontractors and subprocessorsDo you use subcontractors to process our data? List them.5.19, 5.20, 5.21The list of subprocessors with what each does, where it processes and what data it reaches, the contract terms that flow down, and the notice route for changes.
Assessing your own suppliersHow do you assess the security of your own critical suppliers?5.22The supplier assessment procedure, the tiering of suppliers by the data they reach, and the last assessment record for each critical supplier.