Purpose

Translate the CBCS outsourcing guideline into a testable BCMS requirement for outsourcing governance and control.

Normative

Bitkaya shall ensure that outsourcing arrangements protect confidential, personal and otherwise sensitive information through appropriate contractual, technical and organizational measures.

Descriptive

Controls should address confidentiality, legal data-protection obligations, data storage and processing locations, data availability and integrity, security requirements, encryption where needed, access controls, breach or adverse event reporting and secure return, deletion or transfer of data at exit.

Source reference: CBCS Guideline on Outsourcing, Article 5, Article 11, Article 13, Article 18, Article 19, Article 21, Article 29 and Appendix 5.

Assurance Assertions

  • Outsourced data and systems are classified by sensitivity and required protection level.
  • Contractual clauses require protection of confidential and personal data.
  • Data location, access, retention, return and deletion obligations are documented.

Relationships

Assurance

  • Source verified: yes
  • Implementation linked: yes; remaining operational follow-up is tracked in ISS-OUT-001 where applicable
  • Wording unambiguous: approved

History

  • 2026-07-25: Created from SRC-OUT-001.
  • 2026-07-25: Linked outsourcing operational implementation objects derived from the Bitkaya outsourcing manual.
  • 2026-07-25: Approved outsourcing requirement for BCMS use.