Skip to main content
TPM

Third-Party Management

43 controls

Execute Supply Chain Risk Management (SCRM) practices to assess, select, contract, monitor and manage trustworthy third parties for product and service delivery.

SCF # Control Name Weight NIST CSF Frameworks
TPM-01 Third-Party Management Policy 10 — Critical Govern 5
TPM-02 Third-Party Management 10 — Critical Govern 122
TPM-03 Acquisition Strategies, Tools & Methods 9 — Critical Identify 45
TPM-04 Supply Chain Risk Management (SCRM) 9 — Critical Identify 71
TPM-04.1 Processes To Address Weaknesses or Deficiencies 9 — Critical Identify 35
TPM-04.2 Limit Potential Harm 9 — Critical Identify 28
TPM-05 Security, Compliance & Resilience Outsourcing Limitations 7 — High Govern 3
TPM-05.1 Outsourcing Non-Essential Functions or Services 3 — Low Protect 7
TPM-06 Supplier Diversity 3 — Low Protect 13
TPM-07 Adequate Supply 9 — Critical Protect 5
TPM-08 Third-Party Inventories 8 — High Identify 50
TPM-09 Third-Party Criticality Assessments 9 — Critical Identify 65
TPM-10 Third-Party Risk Assessments & Approvals 9 — Critical Identify 80
TPM-11 Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix 8 — High Identify 61
TPM-12 Third-Party Services 10 — Critical Identify 84
TPM-12.1 Conflict of Interests 8 — High Identify 20
TPM-12.2 Third-Party Processing, Storage and Service Locations 10 — Critical Identify 45
TPM-12.3 Third-Party Authentication Practices 8 — High Protect 5
TPM-12.4 External Connectivity Requirements - Identification of Ports, Protocols & Services 7 — High Identify 27
TPM-13 Third-Party Personnel Security 9 — Critical Identify 24
TPM-14 Third-Party Contract Requirements 10 — Critical Identify 124
TPM-14.1 Contract Flow-Down Requirements 9 — Critical Protect 53
TPM-14.2 Provider Contingency Plan 5 — Medium Protect 16
TPM-15 Review of Third-Party Services 9 — Critical Identify 87
TPM-16 Third-Party Scope Review 10 — Critical Identify 29
TPM-17 Managing Changes To Third-Party Services 8 — High Identify 54
TPM-18 Third-Party Deficiency Remediation 9 — Critical Identify 30
TPM-19 Break Clauses 9 — Critical Protect 28
TPM-20 Foreign Ownership, Control or Influence (FOCI) 6 — Medium Protect 0
TPM-20.1 Ownership Change Monitoring 6 — Medium Identify 0
TPM-20.2 Ownership Change Provisions 6 — Medium Protect 0
TPM-21 Third-Party Incident Response & Recovery Capabilities 8 — High Identify 26
TPM-21.1 Security Compromise Notification Agreements 9 — Critical Detect 46
TPM-22 First-Party Declaration (1PD) 7 — High Identify 20
TPM-23 Third-Party Attestation (3PA) 5 — Medium Govern 17
TPM-24 Terminating Third-Party Relationships 8 — High Govern 1
TPM-24.1 Third-Party Transition Planning 6 — Medium Identify 0
TPM-24.2 Technology Assets, Applications, Services and Data (TAASD) Portability 7 — High Recover 0
TPM-24.3 Technology Assets, Applications, Services and Data (TAASD) Disposition 8 — High Protect 0
TPM-24.4 Third-Party Access Revocation 9 — Critical Protect 0
TPM-24.5 Third-Party Knowledge & Operational Transfer 6 — Medium Recover 0
TPM-24.6 Third-Party Exit Obligations Management 7 — High Govern 0
TPM-24.7 Third-Party Exit Contingencies 7 — High Recover 0

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.