The organization should regularly review security protection agreements with counterparties to ensure they remain adequate in light of changed circumstances, such as new threats, technological advancements, or regulatory changes.
If a counterparty fails to comply with the security protection agreement, the organization must take appropriate measures to ensure its own security protection requirements are still met. These measures may include implementing compensating controls, escalating the issue, or re-evaluating the partnership.