How are least-privilege and need-to-know determined for CSP personnel?
Do you design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privileged access for all personnel within your supply chain?