supply-chain Controls
17 controls across 3 frameworks.
CISA CPG
Third-party vendors are required to meet minimum security standards
Governance and Training / Governance and Training
Third-party software and services are inventoried and assessed for risk
Supply Chain / Supply Chain
Vendor contracts include minimum cybersecurity requirements
Supply Chain / Supply Chain
NIST CSF
External service provider activities and services are monitored to detect potentially adverse events
Detect / Continuous Monitoring
A cybersecurity supply chain risk management program is established
Govern / Cybersecurity Supply Chain Risk Management
Supply chain risk management plans include provisions for activities after a supplier relationship ends
Govern / Cybersecurity Supply Chain Risk Management
Cybersecurity roles and responsibilities for suppliers and partners are established and coordinated
Govern / Cybersecurity Supply Chain Risk Management
Supply chain risk management is integrated into enterprise risk management processes
Govern / Cybersecurity Supply Chain Risk Management
Suppliers are known and prioritized by criticality
Govern / Cybersecurity Supply Chain Risk Management
Cybersecurity requirements are integrated into contracts with suppliers
Govern / Cybersecurity Supply Chain Risk Management
Due diligence is performed before entering into supplier relationships
Govern / Cybersecurity Supply Chain Risk Management
Risks from suppliers are assessed, monitored, and responded to throughout the relationship
Govern / Cybersecurity Supply Chain Risk Management
Relevant suppliers are included in incident planning, response, and recovery activities
Govern / Cybersecurity Supply Chain Risk Management
Supply chain security practices are monitored throughout the technology product and service life cycle
Govern / Cybersecurity Supply Chain Risk Management
Critical suppliers are assessed prior to acquisition
Identify / Risk Assessment
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
Identify / Risk Assessment