Hello all,
I'm sure that this has been discussed many time before, however can anyone provide guidance on suppliers of infrastructure requirements being subject to controls under 8.4 externally provided processes, product or service. As a consultancy business, notwithstanding reports; we have externally provided processes, product or service incorporated into our business. However, I'm being informed that our purchase of IT and Print solutions (our infrastructure) should be subject to 8.4 requirements. I cant see that the standard explicitly makes this link as it often does cross reference requirements.
I'm sure that this has been discussed many time before, however can anyone provide guidance on suppliers of infrastructure requirements being subject to controls under 8.4 externally provided processes, product or service. As a consultancy business, notwithstanding reports; we have externally provided processes, product or service incorporated into our business. However, I'm being informed that our purchase of IT and Print solutions (our infrastructure) should be subject to 8.4 requirements. I cant see that the standard explicitly makes this link as it often does cross reference requirements.