Data and content
Feeds, reference data and content the business decides on. The dependency is on accuracy and availability rather than access, and the substitute is rarely a like-for-like swap.
Categories in this family
6- Advertising and analytics platforms standard
The platforms that run campaigns and measure the website and product, collecting behavioural data as they do. - Credit bureau and identity data critical
Credit, identity and screening data the business decides customers on, used inside regulated processes with their own record-keeping rules. - Geospatial and satellite data standard
Maps, imagery, addresses and location feeds that route, verify and monitor the physical world the business operates in. - Health data and clinical content critical
Clinical records, results and reference content that care or insurance processes depend on, under health-specific privacy law. - Market and reference data critical
The prices, rates and reference data that valuation, trading and reconciliation run on. - Research, reports and content standard
Subscriptions to research, news, standards and intelligence the business reads and decides on.
What reaches this family
| DORA | Attaches to contractual arrangements for ICT services: cloud, software, network, managed services and data feeds. A supply of hardware, a bank or a courier is recorded in the register only where a service element sits in the contract. On every vendor here: DORA Art. 28, DORA Art. 30. |
|---|---|
| NIS2 | Attaches to every direct supplier and service provider of the entity, whatever it supplies; the depth of the assessment follows the access and the criticality. On every vendor here: NIS2 Art. 21(2)(d). |
| SP 800-161 | Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access. On every vendor here: SP 800-161 SR-6, SP 800-161 SR-8, SP 800-161 SA-4, SP 800-161 SR-13, SP 800-161 SA-9, SP 800-161 CA-3. |
| ISO 27001 | Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default. On every vendor here: ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.22. |
Register the vendors in this family
Paste the list; every vendor in this family is placed in its category, given its share of spend and systems and the country it lands in, and carries the obligation rows above. Eight vendors free, no account.
Build my vendor register