id: "GV.SC-02" title: "Supply Chain Risk Management" function: "GV" function_name: "Govern" category: "GV.SC" category_name: "Supply Chain Risk Management" description: "Cybersecurity requirements are established for suppliers and third-party partners." controls: - SA-1 - SA-3 - SA-4 - SR-1 - SR-3 - SR-4 - SR-5
GV.SC-02: Supply Chain Risk Management
Description
Cybersecurity requirements are established for suppliers and third-party partners.
Category Context
Function: GV — Govern Category: GV.SC — Supply Chain Risk Management
Cybersecurity supply chain risk management processes are established and implemented.
Mapped SP 800-53 Controls
- SA-1 (System and Services Acquisition) — View Control
- SA-3 (System and Services Acquisition) — View Control
- SA-4 (System and Services Acquisition) — View Control
- SR-1 (Supply Chain Risk Management) — View Control
- SR-3 (Supply Chain Risk Management) — View Control
- SR-4 (Supply Chain Risk Management) — View Control
- SR-5 (Supply Chain Risk Management) — View Control