NIST SP 1800-32
NIST SP 1800-32: Supply Chain & Configuration

NIST SP 1800-32 NIST1800-32-24: Vulnerability assessment for critical systems

Vulnerability assessment for critical systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 234 controls across 114 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

  • RMI-DD-2 Supply Chain Information Collection
  • RMI-DD-3 Red Flag Review
  • RMI-MS-2 Cobalt Standard
  • RMI-RMAP-2 Risk-Based Audit Approach
  • RMI-SEG-2 Environmental Standards
  • RMI-SEG-3 OHS and Governance

API 1164 · 5 controls

  • API1164-07 Remote Access
  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • API1164-24 Vulnerability assessment for critical systems

IEC 62443 · 5 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • IEC62443-24 Vulnerability assessment for critical systems
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P1-S1 Advance Electronic Information
  • P2-S1 Partnership

ISO/IEC 23894:2023 · 4 controls

  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation
  • ISO23894-A.6 AI System Security

ISO/IEC 27003:2017 · 4 controls

  • ISO27003-4.2 Understanding the needs and expectations of interested parties
  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.1 Operational planning and control
  • ISO27003-8.2 Information security risk assessment

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

NIST SP 800-30 · 3 controls

  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • SSAE18-CC3.1 CC3.1 - COSO Principle 6: Risk Identification
  • SSAE18-CC3.2 CC3.2 - COSO Principle 7: Risk Analysis
  • SSAE18-SOC1-02 Risk Assessment

Solvency II · 3 controls

  • SII-P2-09 Outsourcing Requirements
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance

South Korea ISMS-P · 3 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • ISMSP-SYS-04 Vulnerability Management
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.I.OR.205 Information Security Risk Assessment
  • CJIS-17 Risk Assessment
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment

NIST SP 800-37 · 2 controls

  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework
  • ORSA-S2 Guidance Manual Section 2: Insurer's assessment of risk exposures

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-3 Supply Chain Management
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • SOCI-S30CU Vulnerability assessments
  • IM8-SEC.4 Vulnerability Management
  • IM8-TPM.4 Supply Chain Risk Management
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • UKOPRES-3 Self-Assessment and Board Engagement
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • SEMD-PS-3 Supply Chain Security
  • SEMD-SP-2 Risk Identification and Assessment
  • UNESCO-AI-PA1 Ethical Impact Assessment
  • UNESCOAI-1 Principles 1-3: Proportionality, Safety, Fairness
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • 4.3.1 Risk Assessment and Impact Analysis
  • ACQ.4 Supplier Monitoring
  • Mat 03 Responsible Sourcing of Materials

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

FedRAMP High · 1 control

  • RA-1 Policy and Procedures

FedRAMP Moderate · 1 control

  • RA-1 Policy and Procedures
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

GDPR · 1 control

  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)

ISO 27799:2025 · 1 control

  • ISO27799-06 Security management process and risk analysis
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-50001-8.3 Procurement

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity

NIST SP 800-190 · 1 control

NIST SP 800-39 · 1 control

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments

NIST SP 800-66 · 1 control

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training

PDPA Singapore · 1 control

  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 1 control

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management

POPIA · 1 control

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement
  • PICERL-P2 Risk Assessment
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SOC-CY-DC5 Risk Assessment Process

Saudi Arabia PDPL · 1 control

  • SA-PDPL-21 Data protection impact assessments
  • SCA-S10 Annual Risk Assessment

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • Standard 2 Data Protection Impact Assessments
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UKGAMBLE-4 Resilience and Incident Response
  • s.54(5) Statement Content Requirements
  • UK-TSA-NET-03 Supply Chain Security
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • CPSC-RA.3 Lifecycle Risk Assessment

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 1 control

  • VIETNAMPDP-3 Data Subject Rights

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIST SP 1800-32: Supply Chain & Configuration

Query this from an agent

The graph holds this control, the 234 it maps to, and the evidence behind each claim, over MCP and REST.