(a)OVERSIGHT OF THE CONTRACTED ORGANISATION In order to exercise oversight of the contracted organisation, the competent authority should have:
(1)a process to ensure compliance with the provisions regarding contracted activities contained in this Regulation;
(2)a structured process to follow the expected execution of the contract that includes:
(i)definition and agreement of the scope of the activities;
(ii)definition of the roles and responsibilities of the parties (i.e. competent authority and contracted organisation);
(iii)definition and review of KPIs;
(iv)reaction to deviation from contractual obligations;
(v)performance of compliance audits, according to predefined scope and objectives, with the aim of evaluating operational and associated assurance activities;
(vi)provision of feedback on the result of the compliance audits both within the competent authority and to the contracted organisation, and response to findings. The feedback on the outcome of the compliance audits within the competent authority should reach the person of the competent authority as identified in IS.AR.225(a) to ensure proper monitoring of the response to findings (i.e. implementation of corrective actions) or, if deemed necessary, termination of the contract. Note: The right of the competent authority to conduct compliance audits of the contracted organisation should be included in the contract between the parties.
(b)MANAGEMENT OF THE RISKS ASSOCIATED WITH THE CONTRACTED ACTIVITIES In order to properly manage the risks associated with the contracted activities, the competent authority should meet the following criteria:
(1)A prior assessment of the suppliers is conducted before outsourcing any information security management activities. The assessment should evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the activities to be contracted.
(2)There is an assessment of the risks associated with the provision of the contracted activities that has been agreed between the competent authority and the contracted organisation.
(3)The competent authority establishes and maintains appropriate information security communication channels with the contracted organisation.