NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.SC-06: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 80 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 15 controls

FedRAMP High · 8 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-11 Component Authenticity (SR-11)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 8 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-11 Component Authenticity (SR-11)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

ISO 27001:2022 · 5 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services

CIS Controls v8 · 4 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.3 Classify Service Providers
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers

SOC 2 · 4 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • CPS230-43 Due Diligence Before Entering or Modifying a Material Arrangement
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-P15 Precondition for Reliance on a Service Provider
  • ISM-1567 Excluding high risk suppliers
  • ISM-1568 Suppliers committed to product security
  • ISM-1632 Suppliers with a strong security track record

NIST SP 800-161 Rev 1 · 3 controls

  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management
  • ANSSI-HYG-42 Prefer Products and Services Qualified by ANSSI

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-P22 Evaluation of Third Party Control Design
  • SEC06-BP02 Provision compute from hardened images
  • SEC11-BP05 Centralize services for packages and dependencies

ISO 22301:2019 · 2 controls

  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment

ISO 27002:2022 · 2 controls

  • 5.19 Information security in supplier relationships
  • 5.21 Managing information security in the ICT supply chain

ISO 27701:2019 · 2 controls

  • 6.12.1 Information security in supplier relationships
  • 8.5.8 Change of subcontractor to process PII

NIST SP 800-172 · 2 controls

  • 3.11.7e Supply Chain Risk Management Plan
  • 3.14.3e Include Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks

NIST SP 800-218 · 2 controls

C5 (Germany) · 1 control

  • C5-SSO-02 Risk assessment of service providers and suppliers

DORA · 1 control

GDPR · 1 control

HIPAA Security Rule · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

NIS2 Directive · 1 control

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
  • ID.SC-1 ID.SC-1: Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
  • 03.17.02 Acquisition Strategies, Tools, and Methods
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

PCI DSS 4.0 · 1 control

  • 12.8.3 12.8.3 Due diligence before engaging TPSPs

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.SC-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 80 it maps to, and the evidence behind each claim, over MCP and REST.