The CPSC should develop and implement policies and procedures to periodically reviewsecurity packages from external service providers (such as those hosting cloud, sharedservices, and third-party systems) to ensure that the risks posed by the external serviceprovider are within the CPSC’s risk appetite and tolerance.
Report
Date Issued
Oversight.gov UUID
fd669bca-dd89-42cb-98af-6e4c134eaacb
Status
Closed
Recommendation Number
4
Sync
No
Questioned Costs
0
Significant Recommendation
Off