NIST SP 800-171 Rev 3
03.17 SR (Supply Chain Risk Management)

NIST SP 800-171 Rev 3 03.17.03: Supply Chain Requirements and Processes

Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes; enforce flow-down of supply chain requirements to subcontractors.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 48 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-161 Rev 1 · 4 controls

  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements
  • CPS230-P48 Required Content of the Service Provider Management Policy

C5 (Germany) · 3 controls

  • C5-DEV-02 Outsourcing of the development
  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties
  • C5-SSO-04 Monitoring of compliance with requirements

CIS Controls v8 · 3 controls

  • CIS-15.5 Assess Service Providers
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components

FedRAMP High · 3 controls

  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 3 controls

  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 800-218 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-27 Internal Audit Assessment of Third Party Control Assurance
  • CPS234-P22 Evaluation of Third Party Control Design
  • ASBv3-DS-3 Secure DevOps infrastructure
  • DS-2 Ensure software supply chain security

ISO 27001:2022 · 2 controls

  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services

ISO 27002:2022 · 2 controls

  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the ICT supply chain

NIST SP 800-53 Rev 5 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • CFTC-SS-31 Testing Covers Outsourced Resources and Tester Independence from Providers

HIPAA Security Rule · 1 control

NIS2 Directive · 1 control

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

NIST SP 800-172 · 1 control

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring

SOC 2 · 1 control

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 03.17 SR (Supply Chain Risk Management)

You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done?

NIST SP 800-171 Rev 3 03.17.03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.

Query this from an agent

The graph holds this control, the 48 it maps to, and the evidence behind each claim, over MCP and REST.