Protective Security Policy Framework (PSPF) Release 2026
Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0048: 0048 Use secure and verifiable vendors; CISO approves residual risk

Requirement 0048 (Part Two: Risk, section 6.2.2 Third Party Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): Secure and verifiable third-party vendors, providers, partners and associated services are used unless business operations require use, and the residual risks are managed and approved by the Chief Information Security Officer. Supply chain risk is assessed at the earliest stage of procuring applications, IT and OT equipment and services, covering design to decommissioning; where insecure vendors are operationally required, the CISO manages and approves residual risks.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.