2022-05-20
This document establishes the regulatory framework for assessing an organization's ability to provide secure and reliable technology services. It defines specific evaluation criteria covering IT operations, security policies, data controls, contingency planning, and third-party service provider management. The text details a five-point rating scale ranging from strong performance to critically deficient conditions to guide supervisory assessments of IT support and delivery risks.