💼 GV.SC-07: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
- ID:
/frameworks/nist-csf-v2.0/gv-sc/07
Stats
not available
Description
- Adjust assessment formats and frequencies based on the third party's reputation and the criticality of the products or services they provide
- Evaluate third parties' evidence of compliance with contractual cybersecurity requirements, such as self-attestations, warranties, certifications, and other artifacts
- Monitor critical suppliers to ensure that they are fulfilling their security obligations throughout the supplier relationship lifecycle using a variety of methods and techniques, such as inspections, audits, tests, or other forms of evaluation
- Monitor critical suppliers, services, and products for changes to their risk profiles, and reevaluate supplier criticality and risk impact accordingly
- Plan for unexpected supplier and supply chain-related interruptions to ensure business continuity
Similar
- Sections
/frameworks/nist-csf-v1.1/id-sc/02/frameworks/nist-csf-v1.1/id-sc/04/frameworks/nist-sp-800-53-r5/ra/09/frameworks/nist-sp-800-53-r5/sa/04/frameworks/nist-sp-800-53-r5/sa/09/frameworks/nist-sp-800-53-r5/sr/03/frameworks/nist-sp-800-53-r5/sr/06
Similar Sections (Take Policies From)
Sub Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|