EvidenceSheet

SSO-01 Policies and instructions for controlling and monitoring third parties

Document, communicate and make available policies governing third parties whose services support the cloud service, covering procurement risk assessment, subcontractor classification, security and training obligations, l

4
artefacts
1
held by a system
0
at each review
moderate
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Approved third party control policy with version history and publication record · Vendor register / contract repository

periodic reviewEvidence produced at each review

none for this control

governing documentDocuments that govern the control

  • Distribution list showing which procurement and legal staff received the policy · Vendor register / contract repository
  • Template contract clause library covering security, training and vulnerability obligations · Policy repository / GRC workspace
  • Classification rubric distinguishing subcontractors from other suppliers · Vendor register / contract repository

First move

Start with the 1 of 4 artefacts that already live in a system (Vendor register / contract repository); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SP-03 Exceptions from Existing Policies and Instructions · SSO-02 Risk assessment of service providers and suppliers