Cloud and hosting
Compute, storage, hosting and the edge services everything else runs on. The exit provision and the data location are the two questions a regulator asks first.
Categories in this family
5- Colocation critical
Rack, power, cooling and physical security in a third-party data centre for equipment the business owns. - Content delivery network important
Caching, traffic filtering and denial-of-service protection in front of the public applications. - DNS and domain services critical
Authoritative name resolution, domain registration and certificates: the addresses every other service is reached by. - Infrastructure as a service critical
Rented compute, storage and networking in the provider's data centres, on which the business runs its own systems. - Platform as a service critical
A managed runtime, database or middleware the business builds on, where the provider operates the layer beneath the code.
What reaches this family
| DORA | Attaches to contractual arrangements for ICT services: cloud, software, network, managed services and data feeds. A supply of hardware, a bank or a courier is recorded in the register only where a service element sits in the contract. On every vendor here: DORA Art. 28, DORA Art. 30. |
|---|---|
| NIS2 | Attaches to every direct supplier and service provider of the entity, whatever it supplies; the depth of the assessment follows the access and the criticality. On every vendor here: NIS2 Art. 21(2)(d), NIS2 Art. 21(3), NIS2 Art. 24. |
| SP 800-161 | Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access. On every vendor here: SP 800-161 SR-6, SP 800-161 SR-8, SP 800-161 SA-4, SP 800-161 SR-13, SP 800-161 SA-9, SP 800-161 AC-20, SP 800-161 CA-3, SP 800-161 IR-6. |
| ISO 27001 | Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default. On every vendor here: ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.22, ISO 27001 5.23, ISO 27001 5.21. |
Register the vendors in this family
Paste the list; every vendor in this family is placed in its category, given its share of spend and systems and the country it lands in, and carries the obligation rows above. Eight vendors free, no account.
Build my vendor register