Contract Structuring
Entities’ contracts with their third parties include terms and conditions to support the management
of cyber risk and include cyber risks stemming from subcontracting.
Entities should ensure that legal obligations and requirements of relevant authorities and the
expectations of the entity are included in a contract prior to entering into the relationship with a
third party.
In contract terms and conditions related to cyber security, entities may include the scope of the
relationship, performance standards, access, information and audit rights for the entity and its
relevant authorities, reporting provisions, requirements about frequency and types of cyber
resilience tests (e.g. penetration tests, threat-led penetration testing), conditions related to data
location, storage, retention, transfer and disposition, subcontracting, and, to the extent possible,
ICT supply chain provisions and termination options. If not otherwise provided for in law,
contractual agreements should ensure that the entity and relevant authorities are provided with the
information necessary to assess cyber risks arising from third-party relationships, including where
there is a material change in the delivery of the contracted service.
Furthermore, expectations on reporting to the entity any event in the ICT supply chain that could
negatively affect the cyber risk profile of the third party, including cyber incidents, should be
articulated in contracts.
Ongoing Monitoring
Entities monitor changes in criticality and risk, and review contract performance of third parties
on an ongoing basis to manage their cyber risks.
Monitoring should be proportionate to the materiality of the risk and should take into account
changes in the nature of the relationship with the third party. Ongoing monitoring may include
changes to the material cyber vulnerabilities and risks of the third party, its operating environment
and the impact of any cyber threats or incidents. Entities should regularly monitor performance of
the third parties to determine whether it meets the contractual expectations. The entity may collect
and analyse cyber risk metrics and risk indicators to support monitoring.
Where the third party provides critical functions or poses a higher material level of risk to the
entity, more rigorous and frequent monitoring with appropriate oversight should be considered.
Entities should continuously learn and develop their capability to respond to evolving cyber risks
related to third parties and the ICT supply chain.
Element 3: Incident Response
Entities establish and exercise incident response plans that include critical third parties.
The incident response plan of the entity should include ways to detect and collect information about
cyber incidents involving third parties and to communicate with third parties and appropriate
authorities. The plan should also contain roles and responsibilities, and triggers for reporting to
relevant authorities, including national cyber incident response teams.
TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction.
4