| 6728fc5db857f949… | Risk assessment activities must be conducted before the initiation of third-party work so that security gaps are identified prior to engagement. | active | contextual | yes | |
| cb5f291868889942… | The company must conduct a vendor assessment to identify associated risks so that risks tied to third-party vendors are recognized before or during engagement. | active | contextual | yes | |
| face451655d2d0c7… | The company must periodically evaluate the performance of critical third-party vendors so that ongoing vendor effectiveness is assessed. | active | contextual | yes | |
| 7d524cb57e578eca… | The company must review baseline vendor security requirements under its vendor management policy so that minimum security expectations for vendors are evaluated. | active | contextual | yes | |
| 653842be9a3095e7… | The company must maintain an inventory of critical third-party vendors as part of its vendor management policy so that critical vendor relationships are tracked. | active | contextual | yes | |
| d1d3ba7cbe9bde94… | The policy scope covers PYRANA.ai relationships with business partners, suppliers, and third-party vendors, including any third party with access to information, IT assets, IT infrastructure, or facilities of PYRANA.ai and its clients. | active | contextual | yes | |
| c8ea8bc17f999fc6… | The organization actively manages risks related to third-party vendors and their access to PYRANA.ai data so that vendor relationships do not compromise data security. | active | contextual | yes | |
| 830d4468c00ff901… | Due diligence is a required risk category in vendor risk assessments and includes distributed IT environments, legacy or longstanding suppliers, and third-party use of subcontractors. | active | contextual | yes | |
| 895e2f5e5e49053a… | Regulatory requirements are a required risk category in vendor risk assessments because regulators mandate supervision of third-party suppliers for security, privacy, and data protection compliance. | active | contextual | yes | |
| 661b61a9a7e3102a… | Data exposure is a required risk category in vendor risk assessments and refers to incorrectly classified data and unidentified data that could be exposed to the third party. | active | contextual | yes | |
| 9d82432f859505bb… | Business continuity is a required risk category in vendor risk assessments and concerns availability as third-party services and solutions become more integrated into the company’s core offering or service. | active | contextual | yes | |
| 0831a6db2582ba18… | Monitoring gaps are a required risk category in vendor risk assessments and include periodic assessments, ongoing monitoring, incident notification, offboarding, adherence, and SLA appropriateness. | active | contextual | yes | |
| 223895ea9a6f1c74… | Information security is a required risk category in vendor risk assessments and includes assessing third-party controls for security, privacy, confidentiality, and availability of shared data. | active | contextual | yes | |
| 273e26d92f8e6975… | Executive management must review identified risks together with mitigation strategies or risk acceptance decisions before the organization engages with vendors. | active | contextual | yes | |
| 46b9da779e94aec6… | Before outsourcing PYRANA.ai processes or services to a third party or allowing third-party access to organizational information or systems, the involved risks must be clearly identified and documented. | active | contextual | yes | |
| b565d0191d55ba41… | The due diligence process must address all relevant aspects of the service provider, including qualitative and quantitative factors, so that outsourcing decisions consider comprehensive provider risk information. | active | contextual | yes | |
| e8b06c8bc474db7a… | When selecting a service provider or substantially amending or renewing a contract or outsourcing agreement, PYRANA.ai is expected to perform a due diligence process that fully assesses outsourcing risks. | active | contextual | yes | |
| 4fa9a631a92c70d4… | PYRANA.ai performs internal due diligence to determine the nature and scope of outsourced business activity and its relationship to the rest of the in-scope activities. | active | contextual | yes | |
| 9c043f682529f1f7… | The purpose of third-party risk assessments is to ensure PYRANA.ai business data is properly protected from unauthorized access, use, and modification. | active | contextual | yes | |
| 8482ccb5b71dc48a… | Risk assessment activities must be completed before third-party work begins and repeated annually so that gaps between third-party security controls and PYRANA.ai information security standards or regulatory requirements can be identified. | active | contextual | yes | |
| cd7f1ba895716db0… | PYRANA.ai conducts risk assessments on all third parties operating within or collaboratively with the PYRANA.ai environment so that vendor-related risks are evaluated across the environment. | active | contextual | yes | |
| fdf6cd9ac3af3be0… | The company’s vendor management policy requires conducting vendor assessments to identify associated risks so that third-party risk exposure is understood. | active | contextual | yes | |
| 94b8e44168b11245… | The company’s vendor management policy requires periodically evaluating the performance of critical third-party vendors so that ongoing vendor effectiveness is monitored. | active | contextual | yes | |
| 0b08e50e8d312203… | The company’s vendor management policy requires reviewing baseline vendor security requirements so that minimum security expectations for vendors are assessed. | active | contextual | yes | |
| 5370019de58f7cbe… | The company’s vendor management policy requires maintaining an inventory of critical third-party vendors so that important vendor relationships remain tracked. | active | contextual | yes | |
| 1e28d631b3b588ba… | The policy scope includes any third party with access to information, IT assets, IT infrastructure, or facilities of PYRANA.ai and its clients so that all relevant external access is governed. | active | contextual | yes | |
| 0cdaa74230446ca9… | The scope of the policy includes PYRANA.ai’s relationships with business partners, suppliers, and third-party vendors, which are collectively defined as vendors or third-parties. | active | contextual | yes | |
| 8265cea296e9d7b0… | The policy also aims to identify elements of vendor management, due diligence, risk assessments, and contract management so that third-party relationships are governed comprehensively. | active | contextual | yes | |
| 2261c2e7a022ea14… | The purpose of the vendor management policy is to define guidelines for maintaining the security of organizational information systems and data when PYRANA.ai enters arrangements with third-party suppliers or vendors. | active | contextual | yes | |
| 16e206c457c741bf… | The organization actively manages risks related to third-party vendors and their access to PYRANA.ai data so that vendor-related exposure to organizational information is controlled. | active | contextual | yes | |
| 06de364f6b319181… | Risk assessments should consider due diligence risk factors, including distributed IT environments, legacy or longstanding suppliers, and the third party’s use of subcontractors. | active | contextual | yes | |
| d6093c45a7cc10d5… | Risk assessments should consider regulatory requirements risk because regulators mandate supervision of third-party suppliers for security, privacy, and data protection compliance. | active | contextual | yes | |
| 745c17b0f1549951… | Risk assessments should consider data exposure risk, including incorrectly classified data and unidentified data that could be exposed to the third party. | active | contextual | yes | |
| e7134c9d5b4b2e73… | Risk assessments should consider business continuity risk, focusing on availability as third-party services and solutions become more integrated into the company’s core offering or provided service. | active | contextual | yes | |
| 371ea34148bf4df7… | Risk assessments should consider monitoring gaps risk, including periodic assessments, ongoing monitoring, incident notification, offboarding, adherence, and the appropriateness of service level agreements. | active | contextual | yes | |
| 33575fa5f76457d4… | Risk assessments should consider information security risk, defined as evaluating third-party controls related to security, privacy, confidentiality, and availability of shared data. | active | contextual | yes | |
| f2a2685b036dec56… | Executive management must review identified risks together with mitigation strategies or determine whether the risks are acceptable before the organization engages with vendors. | active | contextual | yes | |
| 833f44c03f9a31ef… | Before outsourcing PYRANA.ai processes or services to a third party or allowing third-party access to organizational information or systems, the involved risks must be clearly identified and documented so that outsourcing decisions are based on explicit risk records. | active | contextual | yes | |
| eb892343ae110893… | When selecting a service provider or substantially amending or renewing a contract or outsourcing agreement, PYRANA.ai is expected to perform a due diligence process that fully assesses outsourcing risks and addresses all relevant aspects of the service provider, including qualitative and quantitative factors. | active | contextual | yes | |
| 6c445decc1f1f865… | PYRANA.ai performs internal due diligence to determine the nature and scope of business activity being outsourced and its relationship to the rest of the in-scope activities. | active | contextual | yes | |
| 6f5ba4dbd1f77de3… | Before granting third-party access to the PYRANA.ai network and systems, the organization must conduct a risk assessment of network connectivity so that access-related technical risks are evaluated in advance. | active | contextual | yes | |
| 1d6d64e03b0bb4c6… | The purpose of third-party risk assessments is to ensure PYRANA.ai business data is properly protected from unauthorized access, use, and modification during vendor relationships. | active | contextual | yes | |
| 85b3eba7848830e7… | Risk assessment activities must be completed before third parties begin work and repeated annually so that gaps between third-party security controls and PYRANA.ai information security standards or regulatory requirements can be identified. | active | contextual | yes | |
| 4906421812aa6d24… | PYRANA.ai conducts risk assessments on all third parties operating within or collaboratively with the PYRANA.ai environment so that third-party risks are evaluated across the environment. | active | contextual | yes | |
| 347d93bcb5244551… | The company’s vendor management policy requires conducting vendor assessments to identify associated risks so that risks from third-party relationships are recognized before and during engagement. | active | contextual | yes | |
| 2784ca55ea2c1ff2… | The company’s vendor management policy requires periodically evaluating the performance of critical third-party vendors so that ongoing vendor effectiveness can be assessed. | active | contextual | yes | |
| 2f552a827796dfd9… | The company’s vendor management policy requires reviewing baseline vendor security requirements so that minimum security expectations for vendors are evaluated. | active | contextual | yes | |
| 59fee753cc278b80… | The company’s vendor management policy requires maintaining an inventory of critical third-party vendors so that critical vendor relationships are tracked and managed. | active | contextual | yes | |
| 33933f4b9e376efe… | The policy scope covers PYRANA.ai’s relationships with business partners, suppliers, and third-party vendors, including any third party with access to information, IT assets, IT infrastructure, or facilities of PYRANA.ai and its clients. | active | contextual | yes | |
| b942745b580f92b7… | This policy establishes guidelines for maintaining the security of organizational information systems and data when PYRANA.ai enters arrangements with third-party suppliers or vendors so that vendor management, due diligence, risk assessments, and contract management are addressed. | active | contextual | yes | |