Skip to main content

💼 GV.SC-06: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

  • Contextual name: 💼 GV.SC-06: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • ID: /frameworks/nist-csf-v2.0/gv-sc/06
  • Located in: 💼 Cybersecurity Supply Chain Risk Management (GV.SC)

Description​

  1. Perform thorough due diligence on prospective suppliers that is consistent with procurement planning and commensurate with the level of risk, criticality, and complexity of each supplier relationship
  2. Assess the suitability of the technology and cybersecurity capabilities and the risk management practices of prospective suppliers
  3. Conduct supplier risk assessments against business and applicable cybersecurity requirements
  4. Assess the authenticity, integrity, and security of critical products prior to acquisition and use

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-sc/01
    • /frameworks/nist-sp-800-53-r5/sa/04
    • /frameworks/nist-sp-800-53-r5/sa/09
    • /frameworks/nist-sp-800-53-r5/sr/05
    • /frameworks/nist-sp-800-53-r5/sr/06

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST CSF v1.1 → 💼 ID.SC-1: Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
💼 NIST SP 800-53 Revision 5 → 💼 SA-4 Acquisition Process12
💼 NIST SP 800-53 Revision 5 → 💼 SA-9 External System Services811
💼 NIST SP 800-53 Revision 5 → 💼 SR-5 Acquisition Strategies, Tools, and Methods2
💼 NIST SP 800-53 Revision 5 → 💼 SR-6 Supplier Assessments and Reviews1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags