Skip to main content

ER-64 Sample Vendor Assessments for a Sample of Critical Vendors

C
Written by Claudio Morsella
Updated this week

Vendor Assessments for a Sample of Critical Vendors

For each sampled critical vendor, provide the vendor assessments that were performed and the vendor reports that were reviewed as part of the vendor assessments.

The evidence should demonstrate the following:

  • The compliance report that was reviewed for the vendor (e.g., SOC 2, Type I/II, SOC 1, Type I/II, PCI DSS, ISO 27001 Certificate)

  • The date the vendor review took place

  • The results of the review including any exceptions or risks that were identified

Associated Unified Control ID

Associated Framework Control

CTRL-1109

LCL-55

Did this answer your question?