2018-04-16 Framework v1.1 Core1
2018-04-16 Framework v1.1 Core1
2018-04-16 Framework v1.1 Core1
Supply Chain Risk Management (ID.SC): ID.SC-3: Contracts with suppliers and third-party
The organization’s priorities, constraints, risk partners are used to implement appropriate
tolerances, and assumptions are established and measures designed to meet the objectives of an
used to support risk decisions associated with organization’s cybersecurity program and Cyber
managing supply chain risk. The organization Supply Chain Risk Management Plan.
has established and implemented the processes
to identify, assess and manage supply chain
risks. ID.SC-4: Suppliers and third-party partners are
routinely assessed using audits, test results, or
other forms of evaluations to confirm they are
meeting their contractual obligations.