Risks from suppliers to essential-function systems are understood and managed. Partially achieved: general supplier risks and the extent of the supply chain including subcontractors are known; suppliers show proportionate security against common threats; relevant contracts carry security obligations; third-party connections meet requirements; incident management covers supply chain incidents; and supplier-held data is protected from common threats. Achieved: deep understanding of the supply chain and wider risks, considering ownership, nationality, partnerships and subcontracting in procurement, supply chain subversion by capable actors, critical suppliers resilient to capable actors, proactive contract management with defined responsibilities, managed third-party connections and data sharing, and mutual incident support.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.