Sekit CSF · Supply Chain Security · Policy
RCF-0316Vendor due diligence
The company formally assesses the security posture of suppliers and vendors before engaging with them
Mapping at a glance
RCF-0316Vendor due diligenceSupply Chain Security · Policy
A.5.19Information security in supplier relationshipsISO/IEC 27001:2022 · Annex A controlsA.5.21Managing information security in the ICT supply chainISO/IEC 27001:2022 · Annex A controlsA.8.30Outsourced developmentISO/IEC 27001:2022 · Annex A controlsGV.SC-01Supply chain risk program establishedNIST CSF 2.0GV.SC-03Supply chain risk integratedNIST CSF 2.0
RCF-0316 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.19Information security in supplier relationshipssupportsRequiring a documented security check of every new supplier before the contract is signed supports A.5.19's due diligence requirement, though it does not cover the ongoing supplier risk management the control also demands.A.5.21Managing information security in the ICT supply chainsupportsDocumented security checks before a contract is signed extend A.5.21's supply chain risk management to the point a new dependency is first introduced.A.8.30Outsourced developmentsupportsThis Sekit policy requires a documented security check of a new supplier before the contract is signed, exactly the oversight A.8.30 requires when development work is outsourced.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.SC-01Supply chain risk program establishedGV.SC-03Supply chain risk integratedGV.SC-04Suppliers known and prioritizedGV.SC-06Due diligence before engagement
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Supply Chain Security controls
Ask Sekura: “What evidence proves RCF-0316?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.