A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST Cybersecurity Framework (CSF) 2.0 2.0
GV.SC
Cybersecurity Supply Chain Risk Management
Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders
| Citation | GV.SC |
|---|---|
| Clé de plateforme | arcate:compliance:requirements/nist-csf/2.0/GV.SC |
| Emplacement dans la source | row 30 of sheet 'CSF 2.0' |
| Publié par | NIST |
Exigences filles
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
Suppliers are known and prioritized by criticality
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement