Security Questionnaire Mapper
Third parties and subprocessors ยท question family

Assessing your own suppliers: the clause the question tests

Whether the supplier selects its own suppliers with care and keeps them overseen during the relationship.

How the customer usually asks it

example

"How do you assess the security of your own critical suppliers?"

Read this question

Anchor clauses

5 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.22 Monitoring, review and change management of supplier services
SOC 2 (Trust Services Criteria)CC9.2 Risk mitigation activities include assessment of vendor and business partner controls
SIG (Shared Assessments)domain T Supply Chain Risk Management
NIST Cybersecurity Framework 2.0GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST SP 800-53 Rev 5SR-6 Supplier assessments and reviews

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The supplier assessment procedure, the tiering of suppliers by the data they reach, and the last assessment record for each critical supplier.

The clauses, with what an assessor asks for

ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an assessor expects: Supplier security monitoring reports; Supplier service review meetings; Supplier change management records; Supplier contractual compliance evidence
Where answers usually fall short: Relying on informal verbal updates; Missing documented approval for supplier changes
Source: ISO/IEC 27001:2022
SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controls

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The vendor and business partner inventory, with risk tiering based on data access and criticality; Due diligence records performed before engagement, at the depth the tier requires; Contractual commitments covering confidentiality, security requirements, incident notification and the right to assess; Evidence of ongoing monitoring, such as review of assurance reports with complementary user entity control consideration, and follow up on exceptions noted in them; Evidence of termination handling, including return or deletion of data and revocation of access
Where answers usually fall short: Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs; Inventory covering vendors known to procurement, missing services engaged directly by teams
Source: SOC 2 (Trust Services Criteria)
SIG domain T Supply Chain Risk Management

What it asks for, in one line (the standard's own text is not quoted here):

Manage risk across the supply chain including subservice organizations, fourth parties, hardware and software providers, and concentration risk, with appropriate due diligence and continuous monitoring.

Evidence an assessor expects: Supplier inventory with risk tiering; Due diligence questionnaires and reports; Continuous monitoring tool outputs; Concentration risk analysis
Where answers usually fall short: No fourth party visibility; Continuous monitoring not actioned
Source: SIG (Shared Assessments)
NIST CSF GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

Evidence an assessor expects: Continuous monitoring evidence for critical suppliers; Periodic reassessment schedule and completion records; Threat intelligence on supplier ecosystem; Performance review minutes with security topics; Findings remediation tracker per supplier
Where answers usually fall short: Continuous monitoring only via marketing dashboards; Reassessments slip beyond cycle
Source: NIST Cybersecurity Framework 2.0
SP 800-53 SR-6 Supplier assessments and reviews

Requires assessment and review, at an organization-defined frequency, of the supply chain risk attached to each supplier or contractor and to the particular system, component or service they deliver.

Evidence an assessor expects: Supplier assessment records covering the supply chain risks of what is provided; Defined assessment frequency and evidence reviews occur at that cadence; Risk ratings and the treatment decisions arising from assessments; Evidence assessments cover subcontractors and fourth party dependencies where relevant
Where answers usually fall short: Assessment performed at onboarding only with no defined review cadence; Assessment covers the supplier's corporate posture but not the specific component supplied
Source: NIST SP 800-53 Rev 5

Other families in third parties and subprocessors