TPR-01Third Parties and Supply Chain
Third-party inventory
Third parties with access to data or systems are inventoried with an owner and a criticality judgement.
Why it exists
You cannot assess a vendor you have not listed.
What usually proves it
Vendor register with owner, data access and criticality.
Smaller organizations
One list, updated when someone signs a new tool.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC9.2
- Fully addressedISO/IEC 27001 Annex A · A.5.19
- Fully addressedNIST Cybersecurity Framework · GV.SC-04
- Fully addressedPCI DSS · 12.8.1
- Fully addressedHIPAA Security Rule · 164.308(b)(1)
- Fully addressedGDPR · Art. 28
- Partially addressedEU AI Act · Art. 25 — Responsibilities along the AI value chain.
- Fully addressedNIST AI Risk Management Framework · GOVERN 6.1