💼 GV.SC-09: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
- ID:
/frameworks/nist-csf-v2.0/gv-sc/09
Stats​
not available
Description​
- Policies and procedures require provenance records for all acquired technology products and services
- Periodically provide risk reporting to leaders about how acquired components are proven to be untampered and authentic
- Communicate regularly among cybersecurity risk managers and operations personnel about the need to acquire software patches, updates, and upgrades only from authenticated and trustworthy software providers
- Review policies to ensure that they require approved supplier personnel to perform maintenance on supplier products
- Policies and procedure require checking upgrades to critical hardware for unauthorized changes
Similar​
- Sections
/frameworks/nist-csf-v1.1/id-sc/01/frameworks/nist-sp-800-53-r5/pm/09/frameworks/nist-sp-800-53-r5/pm/19/frameworks/nist-sp-800-53-r5/pm/28/frameworks/nist-sp-800-53-r5/pm/30/frameworks/nist-sp-800-53-r5/pm/31/frameworks/nist-sp-800-53-r5/ra/03/frameworks/nist-sp-800-53-r5/ra/07/frameworks/nist-sp-800-53-r5/sa/04/frameworks/nist-sp-800-53-r5/sa/09/frameworks/nist-sp-800-53-r5/sr/02/frameworks/nist-sp-800-53-r5/sr/03/frameworks/nist-sp-800-53-r5/sr/05/frameworks/nist-sp-800-53-r5/sr/06
Similar Sections (Take Policies From)​
Sub Sections​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|