Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
STA - Supply Chain Management, Transparency & Accountability

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-STA-08: Supply Chain Risk Management

Reassess the risk each organisation in the supply chain presents on a recurring cycle, not only at onboarding.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 76 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS230-37 Service Provider Management Policy
  • CPS230-39 Register of Material Service Providers
  • CPS230-43 Due Diligence Before Entering or Modifying a Material Arrangement
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers
  • CPS230-P15 Precondition for Reliance on a Service Provider
  • CPS230-P48 Required Content of the Service Provider Management Policy

NIST SP 800-161 Rev 1 · 6 controls

FedRAMP High · 5 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)

FedRAMP Moderate · 5 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 800-53 Rev 5 · 5 controls

ISO 27001:2022 · 4 controls

  • 5.19 Information security in supplier relationships
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 8.30 Outsourced development

ISO 27002:2022 · 4 controls

  • 5.19 Information security in supplier relationships
  • 5.21 Managing information security in the ICT supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 8.30 Outsourced development

CIS Controls v8 · 3 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.3 Classify Service Providers
  • CIS-15.5 Assess Service Providers

DORA · 3 controls

  • DORA-Art.28 ICT third-party risk: general principles
  • DORA-Art.29 Preliminary assessment of ICT concentration risk at entity level
  • DORA-Art.31 Designation of critical ICT third-party service providers

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing
  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility
  • CFTC-SS-5 Systems Development and Quality Assurance Category

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

NIST SP 800-171 Rev 3 · 2 controls

  • 03.17.01 Supply Chain Risk Management Plan
  • 03.17.03 Supply Chain Requirements and Processes

NIST SP 800-172 · 2 controls

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 3.11.7e Supply Chain Risk Management Plan

SOC 2 · 2 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management
  • CBPR-PR-49 Spot checking and monitoring of processors

APPI · 1 control

  • CPS220-17 Group Framework Coverage of Non Regulated Group Entities
  • DS-2 Ensure software supply chain security

C5 (Germany) · 1 control

  • C5-SSO-02 Risk assessment of service providers and suppliers

EU AI Act · 1 control

HIPAA Security Rule · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

ISO 22301:2019 · 1 control

  • 8.2.2 Business impact analysis

ISO 27701:2019 · 1 control

  • 6.12.2 Supplier service delivery management

ISO/IEC 42001:2023 · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

PCI DSS 4.0 · 1 control

  • 12.8.3 12.8.3 Due diligence before engaging TPSPs

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in STA - Supply Chain Management, Transparency & Accountability

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-STA-08 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.