

TPN Assessment Process
What is a TPN Assessment?
A Trusted Partner Network (TPN) Assessment is a cybersecurity supply chain audit aimed at service providers (a.k.a. vendors) where your business' Information Security Management System (ISMS) implementation, risk management philosophy, physical security, digital security, cloud security, secure software development practices, and secure content handling workflows are benchmarked for conformance with the Motion Picture Association (MPA) Content Security Best Practices cybersecurity framework. The assessment process is designed to deliver a comprehensive risk and control treatment report to MPA, CDSA, and ACE member studio content owners including Walt Disney Studios, Sony Pictures, Netflix, Paramount Pictures, Warner Brothers Entertainment, and Universal Pictures. The report details your ISMS implementation, approach to risk and business continuity management, framework control implementation, and control treatment, and identifies areas of non-conformance and unacceptable risk that need to be addressed and remediated. The need to comply with the MPA Content Security Best Practices is strictly voluntary. TPN Assessments are voluntary. TPN Assessment is not an accreditation program.
MPA Content Security Best Practices
The MPA Content Security Best Practices (MPA CSBP) is an ISMS control framework derived from and mapped to AICPA TSC 2017, CSA CCM v4.03, ISO/IEC 27001:2022, ISO/IEC 27002:2022, and NIST 800-53 Rev. 5. MPA CSBP are industry-specific and are designed to be of use by any organisation that is engaged in the Media and Entertainment (M&E) industry supply chain. The framework can be used standalone or blended with other international and regional ISMS/risk governance and management regimes, including ISO/IEC 27001:2022, NIST CSF 1.1 or 2.0, ISACA COBIT, CIS 18, Australian Signals Directorate Essential 8 and Information Security Manual, and Japan NISC Common Standards FY2021.
TPN Assessments based on MPA CSBP v5.3 Control Framework
All TPN Assessments are conducted against MPA CSBP v5.3. The revised framework supersedes and replaces MPA CSBP v4.10. As part of your ISMS implementation, you should download the latest version of the control framework, devise a control mapping, determine which controls apply to your organisation, and then ensure you complete a risk assessment and risk treatment plan against each applicable control.
TPN+ Membership Program
The TPN offers a membership-based subscription model. The new assessment program was launched on February 6, 2023. The assessment program is based on the MPA CSBP v5.3 control framework. The new framework (see above) incorporates facility, application, cloud, and software development cybersecurity controls. To participate in the program you will need to join the TPN, and then download, complete, and submit a TPN Vendor Membership Enrollment Form directly to the TPN. Once that is submitted you will need to pay the annual membership fee based on your annual turnover. Once the fee is paid, you will be granted access to the TPN+ Portal where you will manage and complete Blue Shield and Gold Shield TPN Assessments.
Annual TPN Blue Shield Self-Attestation Cybersecurity Assessment
Once you have joined the TPN as a member, you will complete your Blue Shield self-attestation assessment, optionally uploading necessary documents, policies, procedures, drawings, and other evidence to support your declared cybersecurity posture. Once that is complete, your facility will be able to use the "Blue Shield" to signify participation in the program. You do not need to contact or involve a TPN Accredited Assessor to obtain Blue Shield status. Blue Shield status is valid for 12 months on the proviso you continue to pay your annual membership fee. Please ensure you carefully review the TPN Vendor Membership Enrollment Form to understand the use, requirements, and limitations of Blue Shield.
Biennial TPN Gold Shield Independently Audited Cybersecurity Assessment
The next step, should you wish to pursue it, is to obtain Gold Shield status. This is where your cybersecurity posture disclosed as part of the Blue Shield self-attestation process is scoped, assessed, audited, validated, and verified by a TPN Accredited Assessor. You should contact a TPN Accredited Assessor directly to obtain a quote to complete a Gold Shield TPN Assessment. Under the program, TPN Assessments are conducted directly by a TPN Accredited Assessor against your facility's ISMS posture as disclosed in the TPN+ Portal. All relevant controls found in MPA CSBP v5.3 will be inspected and validated for conformance by your Assessor. The TPN is no longer involved in the payment process. You will pay the TPN Accredited Assessor directly. Gold Shield TPN Assessments must be conducted, completed, and submitted within 15 business days of agreeing to commence the assessment. Once the assessment is complete and approved by the TPN you will be able to use the Gold Shield to signify that your cybersecurity posture has been independently vetted. The onus will be on your business to resolve remediation items promptly. Gold Shield status is valid for 2 years on the proviso you continue to pay your annual membership fee. Please ensure you carefully review the TPN Vendor Membership Enrollment Form to understand the use, requirements, and limitations of Gold Shield.
TPN Blue Shield Process
01. Implement an Information Security Management System
The first thing you will need to do is implement an Information Security Management System (ISMS). To get started, download the control framework via the links below: