Vendor Assessments for a Sample of Critical Vendors
For each sampled critical vendor, provide the vendor assessments that were performed and the vendor reports that were reviewed as part of the vendor assessments.
The evidence should demonstrate the following:
The compliance report that was reviewed for the vendor (e.g., SOC 2, Type I/II, SOC 1, Type I/II, PCI DSS, ISO 27001 Certificate)
The date the vendor review took place
The results of the review including any exceptions or risks that were identified
Associated Unified Control ID | Associated Framework Control |
CTRL-1109 | LCL-55 |