UCF ID: 02044 |
Control Type: Actionable Reports or measurements |
Status: Live |
Metric guidance
Calculation: The calculation for this metric is # of known information security risks that are related to third party relationships / # of security risks.
Calculation source: No authority document source of information exists. The following formula was used: the number of information security risks from the risk assessments that are identified as being related to third-party access to the organization's systems divided by the number of security risks identified during the risk assessment.
The Common Control IDs associated with this metric are as follows:
- • Establish and maintain a policy regarding management of third party services. [UCF Control ID 00789]
• Establish and maintain procedures for establishing, maintaining, and terminating outsourcing contracts. [UCF Control ID 00796]
• Monitor the delivery of services by third parties. [UCF Control ID 00799]
• Establish and maintain third-party software maintenance agreements. [UCF Control ID 01143]
• Report monitoring statistics to the Board of Directors. [UCF Control ID 00676]
Supporting and supported controls
This control directly supports:
- • Establish and maintain an information security requirements metrics program for strategic partners and other third-parties. [UCF Control ID 02043]
There are no supporting controls.
Authority documents complied with:
CISWG Information Security Program Elements, January 10,2005, ISPE11.1; IIA Global Technology Audit Guide (GTAG): Information Technology Controls, § 18.2
US Federal Security Guidance
The organization must measure and report on the percentage of known information security risks that are related to third-party relationships. [ISPE11.1, CISWG Information Security Program Elements, January 10,2005]
General Guidance
The purpose of this measurement is to measure the percentage of known information security risks that are related to third-party relationships. [§ 18.2, IIA Global Technology Audit Guide (GTAG): Information Technology Controls]
Copyright 2005-2009 Unified Compliance Framework™. All rights reserved.
