Sekit CSF · Supply Chain Security · Technical
RCF-0318Vendor due diligence
Technical tools support automated vendor security questionnaires and integrate threat intelligence on supplier risk
Mapping at a glance
RCF-0318Vendor due diligenceSupply Chain Security · Technical
A.5.19Information security in supplier relationshipsISO/IEC 27001:2022A.5.22Monitoring, review and change management of supplier servicesISO/IEC 27001:2022GV.SC-01Supply chain risk program establishedNIST CSF 2.0GV.SC-03Supply chain risk integratedNIST CSF 2.0GV.SC-04Suppliers known and prioritizedNIST CSF 2.0
RCF-0318 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.19Information security in supplier relationshipssupportsUsing questionnaire platforms or vendor risk feeds makes the supplier security check A.5.19 requires faster to run consistently across every in-scope vendor.A.5.22Monitoring, review and change management of supplier servicessupportsVendor risk feeds and shared assessment portals make A.5.22's periodic supplier reviews practical to run consistently instead of an occasional manual exercise.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.SC-01Supply chain risk program establishedGV.SC-03Supply chain risk integratedGV.SC-04Suppliers known and prioritizedGV.SC-06Due diligence before engagement
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Supply Chain Security controls
Ask Sekura: “What evidence proves RCF-0318?”
Also via MCP, free with account