The information security team is having difficulty working with the supplier management team. All other aspects of information security management work very well, but contracts with suppliers are often inadequate.
What is the HIGHEST capability level that the organization’s information security management practice demonstrates?