Managed and professional services
People and services that hold privileged access into the estate or build what runs in it. Their compromise is your incident, which is why every regime looks hardest here.
Categories in this family
6- Consultancy and professional services standard
Advisers, integrators, auditors and lawyers engaged for projects and opinions, holding confidential material for the engagement. - Managed security service provider critical
A third party that monitors and responds to security events on the buyer's behalf, with access to the telemetry and often to the controls. - Managed service provider critical
A third party that runs part of the IT estate day to day, holding administrative access to do it. - Outsourced software development important
A third party that writes or maintains the code the business runs, with access to repositories, pipelines and often production. - Security operations centre critical
The analysts and tooling that watch the estate around the clock, in house or outsourced. - Staff augmentation and contractors standard
Individuals supplied by an agency who work inside the business with staff-like access under the agency's employment.
What reaches this family
| DORA | Attaches to contractual arrangements for ICT services: cloud, software, network, managed services and data feeds. A supply of hardware, a bank or a courier is recorded in the register only where a service element sits in the contract. On every vendor here: DORA Art. 28, DORA Art. 30. |
|---|---|
| NIS2 | Attaches to every direct supplier and service provider of the entity, whatever it supplies; the depth of the assessment follows the access and the criticality. On every vendor here: NIS2 Art. 21(2)(d), NIS2 Art. 21(3). |
| SP 800-161 | Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access. On every vendor here: SP 800-161 SR-6, SP 800-161 SR-8, SP 800-161 SA-4, SP 800-161 SR-13, SP 800-161 SA-9, SP 800-161 PS-7, SP 800-161 MA-4, SP 800-161 AC-20, SP 800-161 IR-6. |
| ISO 27001 | Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default. On every vendor here: ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.22, ISO 27001 5.21. |
Register the vendors in this family
Paste the list; every vendor in this family is placed in its category, given its share of spend and systems and the country it lands in, and carries the obligation rows above. Eight vendors free, no account.
Build my vendor register