TISAX - Trusted Information Security Assessment Exchange
Information Security Management
TISAX - Trusted Information Security Assessment Exchange TISAX-ISM-04: Supplier and Third-Party Management
Manage information security risks in supplier relationships including security requirements in contracts, monitoring, and assessment of supplier security posture.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 80 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition