Skip to main content

πŸ’Ό ID.SC-3: Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization's cybersecurity program and Cyber Supply Chain Risk Management Plan

  • Contextual name: πŸ’Ό ID.SC-3: Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization's cybersecurity program and Cyber Supply Chain Risk Management Plan
  • ID: /frameworks/nist-csf-v1.1/id-sc/03
  • Located in: πŸ’Ό Supply Chain Risk Management (ID.SC)

Description​

Empty...

Similar​

  • Sections
    • /frameworks/iso-iec-27001-2013/15/01/01
    • /frameworks/iso-iec-27001-2013/15/01/02
    • /frameworks/iso-iec-27001-2013/15/01/03
    • /frameworks/nist-sp-800-53-r4/sa/09
    • /frameworks/nist-sp-800-53-r4/sa/11
    • /frameworks/nist-sp-800-53-r4/sa/12
  • Internal
    • ID: dec-c-5eed7e9c

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό ISO/IEC 27001:2013 β†’ πŸ’Ό A.15.1.1 Information security policy for supplier relationships
πŸ’Ό ISO/IEC 27001:2013 β†’ πŸ’Ό A.15.1.2 Addressing security within supplier agreements
πŸ’Ό ISO/IEC 27001:2013 β†’ πŸ’Ό A.15.1.3 Information and communication technology supply chain
πŸ’Ό NIST SP 800-53 Revision 4 β†’ πŸ’Ό SA-9 EXTERNAL INFORMATION SYSTEM SERVICES5
πŸ’Ό NIST SP 800-53 Revision 4 β†’ πŸ’Ό SA-11 DEVELOPER SECURITY TESTING AND EVALUATION8
πŸ’Ό NIST SP 800-53 Revision 4 β†’ πŸ’Ό SA-12 SUPPLY CHAIN PROTECTION15

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.SC-05: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags