Control Objectives: Third Party and supply chain oversight
No control objectives match the current filters.
Categorize all suppliers in the supply chain management program.
SNow
Classification: PreventiveState: Published
Categorize all suppliers in the supply chain management program.
Collect evidence of each supplier's supply chain due diligence processes.
SNow
Classification: PreventiveState: Published
Collect evidence of each supplier's supply chain due diligence processes.
Conduct all parts of the supply chain due diligence process.
SNow
Classification: PreventiveState: Published
Conduct all parts of the supply chain due diligence process.
Consult with Procurement for Contractual Requirements
SNow
Classification: PreventiveState: Published
Consultation with procurement to establish the applicable contractual requirements necessary to ensure the adequate protection of Roche confidential data and legal compliance with the processing of personal data.
Citations (9)
- Addressing information security within supplier agreements
- Confidentiality or non-disclosure agreements
- GV.PO-01
- GV.SC-01
- IT Supplier Audit Reports
- Information security in supplier relationships
- Information transfer
- Legal, statutory, regulatory and contractual requirements
- Quality Agreements with IT Supplier
Document the third parties compliance with the organization's system hardening framework.
SNow
Classification: DetectiveState: Published
Document the third parties compliance with the organization's system hardening framework.
Each ODC Engagement has a completed ODC Screening Assessment
SNow
Classification: PreventiveState: Published
Policies (1)
Each ODC Engagement has an ODC Manager assigned
SNow
Classification: PreventiveState: Published
Policies (1)
Ensure vendor has an ODC Impact Assessment in complete state for the engagement
SNow
Classification: PreventiveState: Published
Policies (1)
Establish and maintain Service Level Agreements with the organization's supply chain.
SNow
Classification: PreventiveState: Published
Establish and maintain Service Level Agreements with the organization's supply chain.
Establish and maintain a Service Level Agreement framework.
SNow
Classification: PreventiveState: Published
Establish and maintain a Service Level Agreement framework.
Establish and maintain a supply chain management policy.
SNow
Classification: PreventiveState: Published
Establish and maintain a supply chain management policy.
Children (9)
- Categorize all suppliers in the supply chain management prog...
- Establish and maintain Service Level Agreements with the org...
- Establish and maintain procedures for establishing, maintain...
- Formalize client and third party relationships with contract...
- Include risk management procedures in the supply chain manag...
- Include third party requirements for personnel security in t...
- Monitor third parties when they deliver services.
- Perform a risk assessment prior to engaging a third party.
- Select suppliers based on their qualifications.
Establish and maintain procedures for establishing, maintaining, and terminating third party contracts.
SNow
Classification: PreventiveState: Published
Establish and maintain procedures for establishing, maintaining, and terminating third party contracts.
Establish and maintain third party transaction authentication procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain third party transaction authentication procedures.
Establish the third party's service continuity.
SNow
Classification: DetectiveState: Published
Establish the third party's service continuity.
Formalize client and third party relationships with contracts or nondisclosure agreements as necessary.
SNow
Classification: DetectiveState: Published
Formalize client and third party relationships with contracts or nondisclosure agreements as necessary.
Children (6)
- Include Change Control clauses as appropriate in third party...
- Include a description of the data or information to be cover...
- Include a reporting structure in third party contracts.
- Include incident management procedures and incident reportin...
- Include text that signatories must meet organizational compl...
- Include third party acknowledgement of their data protection...
In case the manufacturing system is managed by 3rd parties or vendor, the service provider should be assessed against cybersecurity requirements according to respective vendor risk assessment process.
SNow
Classification: IdentifyState: Published
In case the manufacturing system is managed by 3rd parties or vendor, the service provider should be assessed against cybersecurity requirements according to respective vendor risk assessment process.
In case the manufacturing system is managed by 3rd parties the SLA (Service Level Agreement) should be formally defined (e.g. support for incident or failure investigation and remediation).
SNow
Classification: RespondState: Published
In case the manufacturing system is managed by 3rd parties the SLA (Service Level Agreement) should be formally defined (e.g. support for incident or failure investigation and remediation).
Include Change Control clauses as appropriate in third party contracts.
SNow
Classification: PreventiveState: Published
Include Change Control clauses as appropriate in third party contracts.
Include a description of the data or information to be covered in third party contracts.
SNow
Classification: PreventiveState: Published
Include a description of the data or information to be covered in third party contracts.
Include a reporting structure in third party contracts.
SNow
Classification: PreventiveState: Published
Include a reporting structure in third party contracts.
Include business requirements of delivered services in the Service Level Agreement.
SNow
Classification: PreventiveState: Published
Include business requirements of delivered services in the Service Level Agreement.
Include compliance with the organization's access policy as a requirement in third party contracts.
SNow
Classification: PreventiveState: Published
Include compliance with the organization's access policy as a requirement in third party contracts.
Include compliance with the organization's privacy policy in third party contracts.
SNow
Classification: PreventiveState: Published
Include compliance with the organization's privacy policy in third party contracts.
Include incident management procedures and incident reporting procedures in third party contracts.
SNow
Classification: PreventiveState: Published
Include incident management procedures and incident reporting procedures in third party contracts.
Include risk management procedures in the supply chain management policy.
SNow
Classification: PreventiveState: Published
Include risk management procedures in the supply chain management policy.
Include text about access, use, disclosure, and transfer of data or information in third party contracts.
SNow
Classification: PreventiveState: Published
Include text about access, use, disclosure, and transfer of data or information in third party contracts.
Include text that signatories must meet organizational compliance requirements in third party contracts.
SNow
Classification: PreventiveState: Published
Include text that signatories must meet organizational compliance requirements in third party contracts.
Include third party acknowledgement of their data protection responsibilities in third party contracts.
SNow
Classification: DetectiveState: Published
Include third party acknowledgement of their data protection responsibilities in third party contracts.
Include third party requirements for personnel security in third party contracts.
SNow
Classification: DetectiveState: Published
Include third party requirements for personnel security in third party contracts.
Monitor and report on the efficacy of all Service Level Agreements using a Service Level Agreement Monitoring Chart or equivalent.
SNow
Classification: DetectiveState: Published
Monitor and report on the efficacy of all Service Level Agreements using a Service Level Agreement Monitoring Chart or equivalent.
Monitor third parties when they deliver services.
SNow
Classification: DetectiveState: Published
Monitor third parties when they deliver services.
ODC has formally documented Business Continuity and Disaster Recovery Plans
SNow
Classification: PreventiveState: Published
Policies (1)
Perform a risk assessment prior to engaging a third party.
SNow
Classification: DetectiveState: Published
Perform a risk assessment prior to engaging a third party.
Require third parties to maintain a compliance framework equivalent to that of the organization's compliance requirements.
SNow
Classification: DetectiveState: Published
Require third parties to maintain a compliance framework equivalent to that of the organization's compliance requirements.
Review all Service Level Agreements.
SNow
Classification: DetectiveState: Published
Review all Service Level Agreements.
Review all contracts.
SNow
Classification: PreventiveState: Published
Review all contracts.
SOC Report Review
SNow
Classification: DetectiveState: Published
Service provider holds a System and Organization Controls (SOC) report and the report is reviewed on a yearly basis by Roche Information Security.
Select suppliers based on their qualifications.
SNow
Classification: PreventiveState: Published
Select suppliers based on their qualifications.
Third Party and supply chain oversight
SNow
Classification: IT Impact ZoneState: Published
Third Party and supply chain oversight
Vendor Risk Assessment (VRA)
SNow
Classification: PreventiveState: Published
This control mandates a formal assessment to ensure that third-party vendors meet Roche information security, privacy (VSA) and quality (VQA) requirements. This assessment must be performed before the software is used by Roche or connected (access granted) to our network, systems, or data. This proc
Vendor Security Assessment
SNow
Classification: PreventiveState: Published
An assessment conducted to verify whether a vendor meets Roches information security and privacy requirements to process, host, and/or to have access to Roches network which includes business critical or personal data related to its services to Roche.
Citations (6)
Vendor has Cyber risk insurance which covers Data Breaches and Cyber Liability
SNow
Classification: PreventiveState: Published
Policies (1)
Vendor has a formal onboarding and offboarding process for employees as well as contractors working for the ODC
SNow
Classification: PreventiveState: Published
Policies (1)
Vendor has an industry recognized security certification from an accredited third party
SNow
Classification: PreventiveState: Published
Policies (1)
Vendor has an up to date Business Continutiy Plan for the services provided to Roche
SNow
Classification: PreventiveState: Published
Verify third parties meet organizational compliance standards.
SNow
Classification: DetectiveState: Published
Verify third parties meet organizational compliance standards.