SaaS Trust & Service Compliance Management
Service-level attestations, customer security questionnaires, public trust disclosures, sub-processor management, service-privacy commitments, and customer-facing service-resilience commitments for the SaaS offering.
SaaS Trust & Service Compliance Management (BC-4290) is a level-1 business capability in the Software & Technology model. The catalog holds 2 API surface(s) from 2 provider(s) that can perform some part of it. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.
Authorities this capability cites
Cited by the capability model itself. These frameworks are referenced, never redistributed, and citing one does not imply its owner endorses this listing.
- https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2
- https://www.iso.org/standard/27001
- https://cloudsecurityalliance.org/star/
- https://www.fedramp.gov/
Sub-capabilities
Service Attestation Management BC-4290.10
Coordination of service-level attestations such as SOC 2, ISO 27001, and FedRAMP for the SaaS offering.
Customer Security Questionnaire Management BC-4290.20
Stewardship of the questionnaire repository, response authoring, and knowledge base used to answer customer vendor-risk assessments.
Trust Portal & Public Disclosure BC-4290.30
Operation of the customer trust portal, public status disclosures, and document distribution workflows.
Sub-Processor Management BC-4290.40
Inventory, disclosure, and change-notification of sub-processors that handle customer data.
Service Privacy Commitment Management BC-4290.50
Stewardship of data-processing addenda, customer data-flow disclosures, and routing of data-subject requests.
Service Resilience Commitment Management BC-4290.60
Customer-facing service-level commitments, uptime disclosure, and service-credit administration.
Providers that reach this capability
Ordered by rating band. Reach means a provider publishes an API surface that can perform some part of this capability — it is not a claim that any particular organisation has deployed it.