(a)OVERSIGHT OF THE CONTRACTED ORGANISATION In order to exercise oversight of the contracted organisation, the organisation under Part-IS should have:
(1)a process to ensure compliance with the provisions regarding contracted activities contained in this Regulation;
(2)a structured process to follow the expected execution of the contract that includes:
(i)definition and agreement of the scope of the activities;
(ii)definition of the roles and responsibilities of the parties (i.e. contracting and contracted organisation).
(iii)definition and review of key performance indicators;
(iv)reaction to deviation from contractual obligations;
(v)performance of compliance audits, according to the predefined scope and objectives, with the aim of evaluating operational and associated assurance activities.
(vi)provision of feedback on the result of the compliance audits both within the organisation and to the contracted organisation, and response to findings. The feedback on the outcome of the compliance audits within the contracting organisation should reach the accountable manager or, in the case of design organisations, the head of the design organisation, or delegated person(s) to ensure proper monitoring of the response to findings (i.e. implementation of corrective actions) or, if deemed necessary, termination of the contract. Note: The right of the organisation to conduct compliance audits of the contracted organisation should be included in the contract between the parties.
(b)MANAGEMENT OF THE RISKS ASSOCIATED WITH THE CONTRACTED ACTIVITIES In order to properly manage the risks associated with the contracted activities, the organisation should meet the following criteria:
(1)A prior assessment of the suppliers is conducted before outsourcing any information security management activities. The assessment should evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the activities to be contracted.
(2)There is an assessment of the risks associated with the provision of the contracted activities that has been agreed between the organisation under Part-IS and the contracted organisation.
(3)The organisation establishes and maintains appropriate information security communication channels with the contracted organisation.