{
  "node_id": "cis-controls-v8-1-control-15-service-provider-management",
  "title": "CIS Controls v8.1 Control 15: Service Provider Management",
  "domain": "Cybersecurity",
  "version": "8.1.0",
  "last_updated": "2024-06-01",
  "bluf": "CIS Controls v8.1 Control 15: Service Provider Management. CIS Controls 15 focuses on developing a process to evaluate service providers to ensure platforms and data are protected appropriately. Control 15 is one of 18 CIS Controls in version 8.1 (revised June 2024) and is implemented through 7 Safeguards organized across CIS Implementation Groups IG1 (basic, applicable to all enterprises), IG2 (foundational, for resource-constrained enterprises with sensitive data), and IG3 (organizational, for mature enterprises with high-impact data). Each Safeguard maps to specific NIST SP 800-53 Rev 5 controls per the CIS-NIST crosswalk and to NIST Cybersecurity Framework 2.0 outcomes. Implementation evidence is required for SOC 2, FedRAMP, PCI DSS, HIPAA, and most cyber-insurance underwriting assessments. The deterministic workflow below provides the operational schema for verifying CIS Control 15 adoption in the organization.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "cis-controls-v8",
    "nist-sp-800-53-r5",
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022"
  ],
  "primary_citations_count": 6
}