Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Definition of supplier-specific responsible persons

Critical
High
Normal
Low

A responsible person has been appointed for the provider companies, who monitors the provider's activities, communications and compliance with the contract.

Responsible person must have sufficient skills to analyze cyber security requirements depending on the criticality of the provider. Responsible person also ensures that the provider appoints an own responsible person to ensure compliance with the contract and facilitate cooperation.

Connected other frameworks and requirements:
15.2.2: Managing changes to supplier services
ISO 27001
8.1.2: Ownership of assets
ISO 27001
ID.SC-4: Audit suppliers and third-party partners
NIST CSF

Managing changes to supplier services

Critical
High
Normal
Low

The responsible person monitors significant changes in the supplier's operations that may affect the supplier relationship and service level, and thus require other measures. The following aspects are taken into account:

  • direct changes to supplier agreements
  • service content improvements, new technologies or the development of new services
  • significant changes in operating methods (either related to cyber security or other activities)
  • changes in the physical location of the data
  • changes in the supply chain / subcontracting process
Connected other frameworks and requirements:
15.2.2: Managing changes to supplier services
ISO 27001
No items found.