SEA-02.2 ยท Outsourcing Non-Essential Functions or Services

Control Description

Mechanisms exist to identify non-essential functions or services that are capable of being outsourced to external service providers and align with the organization's enterprise architecture and security standards.

Control Question
Assessment question for control validation

Does the organization identify non-essential functions or services that are capable of being outsourced to external service providers and align with its enterprise architecture and security standards?

Control Weighting
3
Validation Cadence
Annual
NIST CSF Function
Protect
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 2 - Operational
Additional Metadata
Applicability (Process):
x