Category A

Category B

Category C

Process

Treatment

Initiate

-NDAs

Per Legal

Per Legal

Per Legal

Screen

-Landscape Survey

Rigorous

Rigorous

Less Rigorous

-Supplier Background Checks

Rigorous

Rigorous

Rigorous

Set-Up

-Compliance Plan

Rigorous

Rigorous

Rigorous

-Communication Plan

Rigorous

Occasional as Needed

Less Frequent

Manage

-Risk/Criticality Monitoring

Frequent Checkpoints

Frequent Checkpoints

Less Frequent Checkpoints

-Relationship Building

Frequent Checkpoints

Occasional as Needed

Less Frequent Checkpoints

-Accountability/Reporting

Frequent Checkpoints

Frequent Checkpoints

Less Frequent Checkpoints

Exit

-Data Protection

Upon exit

-Credential Removal

Upon exit

-Equipment Return

Upon exit