Applying Complementary User Entity Controls (CUECs) to Mitigate Vendor Risks
CPE Credit Eligible
Reviewing a vendor’s SOC report is an important activity that gives insight into the vendor’s control environment. These controls will have certain objectives, some of which can only be achieved through applying complementary user entity controls (CUECs).
Your organization is solely responsible for implementing CUECs, and failing to do so means your organization isn’t protected from known vendor risks. By identifying, reviewing, and mapping vendor CUECs, your organization can ensure the right controls are implemented and help mitigate vendor risks.
Download the infographic to learn:
- What vendor CUECs are
- How to review vendor CUECs
- Tips to map vendor CUECs in your program