Sekit CSF · Supply Chain Security · Policy
RCF-0316Vendor due diligence
The company formally assesses the security posture of suppliers and vendors before engaging with them
Mapping at a glance
RCF-0316Vendor due diligenceSupply Chain Security · Policy
RCF-0316 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.19Information security in supplier relationshipssupportsRequiring a documented security check of every new supplier before the contract is signed supports A.5.19's due diligence requirement, though it does not cover the ongoing supplier risk management the control also demands.A.5.21Managing information security in the ICT supply chainsupportsDocumented security checks before a contract is signed extend A.5.21's supply chain risk management to the point a new dependency is first introduced.A.8.30Outsourced developmentsupportsThis Sekit policy requires a documented security check of a new supplier before the contract is signed, exactly the oversight A.8.30 requires when development work is outsourced.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.SC-01Supply chain risk program establishedGV.SC-03Supply chain risk integratedGV.SC-04Suppliers known and prioritizedGV.SC-06Due diligence before engagement
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Supply Chain Security controls
Ask Sekura: “What evidence proves RCF-0316?”
Also via MCP, free with account