Skip to main content

๐Ÿ’ผ A.15.1.2 Addressing security within supplier agreements

Descriptionโ€‹

All relevant information security requirements shall be established and agreed with each supplier that may access, process, store, communicate, or provide IT infrastructure components for, the organizationโ€™s information.

Similarโ€‹

  • Internal
    • ID: dec-c-05ebc46f

Similar Sections (Give Policies To)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ NIST CSF v1.1 โ†’ ๐Ÿ’ผ ID.BE-1: The organization's role in the supply chain is identified and communicated
๐Ÿ’ผ NIST CSF v1.1 โ†’ ๐Ÿ’ผ ID.SC-1: Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
๐Ÿ’ผ NIST CSF v1.1 โ†’ ๐Ÿ’ผ ID.SC-3: Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization's cybersecurity program and Cyber Supply Chain Risk Management Plan

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags