NIST Cybersecurity Framework 1.1 ID.SC-2: ID.SC-2: Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process
Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process. IDENTIFY (ID) Function, Supply Chain Risk Management (ID.SC) Category. Outcome in the Framework Core of Version 1.1; withdrawn in CSF 2.0 (incorporated into GV.OC-02, GV.SC-03, GV.SC-04, GV.SC-07, ID.RA-10). Added in Version 1.1.
This control maps to 5 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition