Skip to main content

Repository → 💼 NIST CSF v1.1 → 💼 Supply Chain Risk Management (ID.SC)

💼 ID.SC-2: Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process

  • ID: /frameworks/nist-csf-v1.1/id-sc/02

Description

Empty...

Similar

  • Sections
    • /frameworks/iso-iec-27001-2013/15/02/01
    • /frameworks/iso-iec-27001-2013/15/02/02
    • /frameworks/nist-sp-800-53-r4/ra/02
    • /frameworks/nist-sp-800-53-r4/ra/03
    • /frameworks/nist-sp-800-53-r4/sa/12
    • /frameworks/nist-sp-800-53-r4/sa/14
    • /frameworks/nist-sp-800-53-r4/sa/15
  • Internal
    • ID: dec-c-f0f74468

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 ISO/IEC 27001:2013 → 💼 A.15.2.1 Monitoring and review of supplier servicesno data
💼 ISO/IEC 27001:2013 → 💼 A.15.2.2 Managing changes to supplier servicesno data
💼 NIST SP 800-53 Revision 4 → 💼 RA-2 SECURITY CATEGORIZATIONno data
💼 NIST SP 800-53 Revision 4 → 💼 RA-3 RISK ASSESSMENTno data
💼 NIST SP 800-53 Revision 4 → 💼 SA-12 SUPPLY CHAIN PROTECTION15no data
💼 NIST SP 800-53 Revision 4 → 💼 SA-14 CRITICALITY ANALYSIS1no data
💼 NIST SP 800-53 Revision 4 → 💼 SA-15 DEVELOPMENT PROCESS, STANDARDS, AND TOOLS11no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v2.0 → 💼 GV.OC-02: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered7no data
💼 NIST CSF v2.0 → 💼 GV.SC-03: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes10no data
💼 NIST CSF v2.0 → 💼 GV.SC-04: Suppliers are known and prioritized by criticality7no data
💼 NIST CSF v2.0 → 💼 GV.SC-07: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship26no data
💼 NIST CSF v2.0 → 💼 ID.RA-10: Critical suppliers are assessed prior to acquisition26no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (7)

PolicyLogic CountFlagsCompliance
🛡️ Azure Subscription Microsoft Defender For (Managed Instance) Azure SQL Databases is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For App Services is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Containers is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Key Vault is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Servers is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For SQL Servers On Machines is not set to On🟢1🟢 x6no data
🛡️ Azure Subscription Microsoft Defender For Storage is not set to On🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-1a2f62791
✉️ dec-x-9f7d853f1
✉️ dec-x-52ac4ac01
✉️ dec-x-8535d1ff1
✉️ dec-x-a00b4ec91
✉️ dec-x-a04719771
✉️ dec-x-fafadacd1