Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 14th September 2026 at 8:54 am #3479
A new hosting, support, or AI provider can change security and privacy risks. What should the contract require?
14th September 2026 at 12:52 pm #3480Accepted answerRequire notice before any material change to a subprocessor or subcontractor, including the service role, data involved, location, effective date, and relevant controls. Give the buyer time to assess the change and define escalation, mitigation, or exit options when the new risk cannot be accepted. Keep the primary vendor accountable for performance. NIST SP 800-161 Rev. 1 treats supplier relationships and dependencies as cyber supply-chain risk.
15th September 2026 at 4:27 am #3531Community replyWhat makes a subcontractor’s material change significant enough to trigger the notice and objection process?
- AuthorPosts
- You must be logged in to reply to this topic.