CSO tips you off on what to audit inside those who conduct trade so closely with you and what resources to use. The federated enterprise makes a bulletproof perimeter no longer possible. The easiest way to apply the correct information security standard is simply to look at those that you must follow and expect the same from your external service providers. The Australian Governments Department of Defense publishes Information Security Advice For All Levels Of Government The U.S. Department of Health and Human Services, and the NIST Cybersecurity Framework (for the energy/utilities industries)”]
Source: https://www.csoonline.com/article/3048851/how-to-audit-external-service-providers.html

