Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
98 controls
03.01.01
Account management
Access control
3 evidence1 control
03.01.02
Access enforcement
Access control
2 evidence1 control
03.01.03
Information flow enforcement
Access control
2 evidence1 control
03.01.04
Separation of duties
Access control
3 evidence1 control
03.01.05
Least privilege
Access control
2 evidence1 control
03.01.06
Least privilege - privileged accounts
Access control
3 evidence1 control
03.01.07
Least privilege - privileged functions
Access control
2 evidence1 control
03.01.08
Unsuccessful logon attempts
Access control
2 evidence1 control
03.01.09
System use notification
Access control
2 evidence1 control
03.01.10
Device lock
Access control
2 evidence1 control
03.01.11
Session termination
Access control
2 evidence1 control
03.01.12
Remote access
Access control
3 evidence1 control
03.01.16
Wireless access
Access control
2 evidence1 control
03.01.18
Access control for mobile devices
Access control
3 evidence1 control
03.01.20
Use of external systems
Access control
2 evidence1 control
03.01.22
Publicly accessible content
Access control
3 evidence1 control
03.02.01
Literacy training and awareness
Awareness and training
3 evidence1 control
03.02.02
Role-based training
Awareness and training
2 evidence1 control
03.03.01
Event logging
Audit and accountability
3 evidence1 control
03.03.02
Audit record content
Audit and accountability
2 evidence1 control
03.03.03
Audit record generation
Audit and accountability
2 evidence1 control
03.03.04
Response to audit logging process failures
Audit and accountability
2 evidence1 control
03.03.05
Audit record review, analysis, and reporting
Audit and accountability
3 evidence1 control
03.03.06
Audit record reduction and report generation
Audit and accountability
2 evidence1 control
03.03.07
Time stamps
Audit and accountability
2 evidence1 control
03.03.08
Protection of audit information
Audit and accountability
3 evidence1 control
03.04.01
Baseline configuration
Configuration management
2 evidence1 control
03.04.02
Configuration settings
Configuration management
2 evidence1 control
03.04.03
Configuration change control
Configuration management
3 evidence1 control
03.04.04
Impact analyses
Configuration management
2 evidence1 control
03.04.05
Access restrictions for change
Configuration management
2 evidence1 control
03.04.06
Least functionality
Configuration management
2 evidence1 control
03.04.08
Authorized software - allow by exception
Configuration management
2 evidence1 control
03.04.10
System component inventory
Configuration management
2 evidence1 control
03.04.11
Information location
Configuration management
2 evidence1 control
03.04.12
System and component configuration for high-risk areas
Configuration management
2 evidence1 control
03.05.01
User identification, authentication, and re-authentication
Identification and authentication
2 evidence1 control
03.05.02
Device identification and authentication
Identification and authentication
2 evidence1 control
03.05.03
Multi-factor authentication
Identification and authentication
3 evidence1 control
03.05.04
Replay-resistant authentication
Identification and authentication
2 evidence1 control
03.05.05
Identifier management
Identification and authentication
2 evidence1 control
03.05.07
Password management
Identification and authentication
3 evidence1 control
03.05.11
Authentication feedback
Identification and authentication
2 evidence1 control
03.05.12
Authenticator management
Identification and authentication
3 evidence1 control
03.06.01
Incident handling
Incident response
3 evidence1 control
03.06.02
Incident monitoring, reporting, and response assistance
Incident response
3 evidence1 control
03.06.03
Incident response testing
Incident response
2 evidence1 control
03.06.04
Incident response training
Incident response
2 evidence1 control
03.06.05
Incident response plan
Incident response
3 evidence1 control
03.07.04
Maintenance tools
Maintenance
3 evidence1 control
03.07.05
Non-local maintenance
Maintenance
3 evidence1 control
03.07.06
Maintenance personnel
Maintenance
4 evidence1 control
03.08.01
Media storage
Media protection
3 evidence1 control
03.08.02
Media access
Media protection
3 evidence1 control
03.08.03
Media sanitization
Media protection
3 evidence1 control
03.08.04
Media marking
Media protection
3 evidence1 control
03.08.05
Media transport
Media protection
3 evidence1 control
03.08.07
Media use
Media protection
3 evidence1 control
03.08.09
System backup - cryptographic protection
Media protection
3 evidence1 control
03.09.01
Personnel screening
Personnel security
3 evidence1 control
03.09.02
Personnel termination and transfer
Personnel security
3 evidence1 control
03.10.01
Physical access authorizations
Physical protection
3 evidence1 control
03.10.02
Monitoring physical access
Physical protection
3 evidence1 control
03.10.06
Alternate work site
Physical protection
3 evidence1 control
03.10.07
Physical access control
Physical protection
3 evidence1 control
03.10.08
Access control for transmission
Physical protection
3 evidence1 control
03.11.01
Risk assessment
Risk assessment
3 evidence1 control
03.11.02
Vulnerability monitoring and scanning
Risk assessment
3 evidence1 control
03.11.04
Risk response
Risk assessment
3 evidence1 control
03.12.01
Security assessment
Security assessment and monitoring
3 evidence1 control
03.12.02
Plan of action and milestones
Security assessment and monitoring
3 evidence1 control
03.12.03
Continuous monitoring
Security assessment and monitoring
3 evidence1 control
03.12.05
Information exchange
Security assessment and monitoring
3 evidence1 control
03.13.01
Boundary protection
System and communications protection
3 evidence1 control
03.13.04
Information in shared system resources
System and communications protection
3 evidence1 control
03.13.06
Network communications - deny by default - allow by exception
System and communications protection
3 evidence1 control
03.13.08
Transmission and storage confidentiality
System and communications protection
3 evidence1 control
03.13.09
Network disconnect
System and communications protection
3 evidence1 control
03.13.10
Cryptographic key establishment and management
System and communications protection
3 evidence1 control
03.13.11
Cryptographic protection
System and communications protection
3 evidence1 control
03.13.12
Collaborative computing devices and applications
System and communications protection
3 evidence1 control
03.13.13
Mobile code
System and communications protection
3 evidence1 control
03.13.15
Session authenticity
System and communications protection
3 evidence1 control
03.14.01
Flaw remediation
System and information integrity
3 evidence1 control
03.14.02
Malicious code protection
System and information integrity
3 evidence1 control
03.14.03
Security alerts, advisories, and directives
System and information integrity
3 evidence1 control
03.14.06
System monitoring
System and information integrity
3 evidence1 control
03.14.08
Information management and retention
System and information integrity
3 evidence1 control
03.14.09
Dedicated administration workstation
System and information integrity
3 evidence1 control
03.15.01
Policy and procedures
Planning
3 evidence1 control
03.15.02
System security plan
Planning
3 evidence1 control
03.15.03
Rules of behaviour
Planning
3 evidence1 control
03.16.01
Security engineering principles
System and services acquisition
3 evidence1 control
03.16.02
Unsupported system components
System and services acquisition
3 evidence1 control
03.16.03External system servicesITSP.10.171System and services acquisition
Official Requirement
A. Require the providers of external system services used for the processing, storage, or transmission of specified information, to comply with the following security requirements: [Assignment: organization-defined security requirements]. B. Define and document user roles and responsibilities with regard to external system services including shared responsibilities with external service providers. C. Implement processes, methods, and techniques to monitor security requirement compliance by external service providers on an ongoing basis.
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
When using external service providers (cloud vendors, SaaS, managed services), you must require them to meet your security requirements. Roles and responsibilities must be clearly defined. You need an ongoing process to monitor whether external providers continue to comply with your security requirements -- not just a one-time assessment.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control External service provider security management
Implementation Steps
Include security requirements in contracts and service agreements with all external system service providers
Define and document organizational oversight responsibilities and user roles for managing external service relationships
Require external providers to demonstrate compliance through SOC 2 reports, ISO 27001 certificates, or equivalent assurance mechanisms
Implement ongoing monitoring of provider compliance through periodic reviews, automated compliance tools, and contract performance assessments
Tools / Systems
Third-party risk management platform (OneTrust, SecurityScorecard, BitSight)Contract management system with security requirement trackingVendor assessment questionnaires (SIG, CAIQ)GRC platform for ongoing compliance monitoring
Typical Control External service provider security management
Evidence Artifacts
Contracts and agreements with security requirements for external providers
Documented roles and responsibilities for external service oversight