NIST Cybersecurity Framework 1.1 ID.SC-4: ID.SC-4: Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations.
Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations.. IDENTIFY (ID) Function, Supply Chain Risk Management (ID.SC) Category. Outcome in the Framework Core of Version 1.1; withdrawn in CSF 2.0 (incorporated into GV.SC-07, ID.RA-10). Added in Version 1.1.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition