Sekit CSF · Family
Supply Chain Security
15 controls in 5 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0319Contractual security clauses7 mappingsSecurity requirements are formally included in contracts with all suppliers who handle company data or access systemsRCF-0325Offboarding vendors5 mappingsA formal process governs how supplier relationships are ended and access and data are removedRCF-0322Ongoing monitoring7 mappingsThe company formally monitors the security posture of its key suppliers throughout the relationshipRCF-0328Software supply chain (SBOM)6 mappingsThe company formally tracks the software components it uses to manage risks from third-party codeRCF-0316Vendor due diligence8 mappingsThe company formally assesses the security posture of suppliers and vendors before engaging with them
Process
RCF-0320Contractual security clauses6 mappingsContractual security obligations are consistently enforced and suppliers are held accountable for non-complianceRCF-0326Offboarding vendors5 mappingsVendor offboarding is consistently completed to ensure all access is revoked and data is returned or destroyedRCF-0323Ongoing monitoring7 mappingsSupplier security is consistently reviewed through periodic assessments and real-time intelligenceRCF-0329Software supply chain (SBOM)7 mappingsSoftware bills of materials are consistently maintained and reviewed for vulnerable or compromised componentsRCF-0317Vendor due diligence7 mappingsSecurity assessments are consistently conducted at onboarding and reviewed periodically throughout the relationship
Technical
RCF-0321Contractual security clauses5 mappingsTechnical tools manage supplier contract obligations and track compliance with contractual security requirementsRCF-0327Offboarding vendors5 mappingsTechnical controls automate the revocation of supplier access and verify that no residual access remainsRCF-0324Ongoing monitoring6 mappingsTechnical tools provide continuous monitoring of supplier security ratings and alert on significant changesRCF-0330Software supply chain (SBOM)6 mappingsTechnical tools generate and analyse software bills of materials and alert when components with known vulnerabilities are detectedRCF-0318Vendor due diligence6 mappingsTechnical tools support automated vendor security questionnaires and integrate threat intelligence on supplier risk
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in ISO/IEC 42001:2023 — Annex A
This family in Cyber Essentials
Ask Sekura: “What evidence proves Supply Chain Security?”
Also via MCP, free with account