NIST CSF 2.0 · derived mapping target
GV.SC-05Supply chain requirements in contracts
Build clear cybersecurity requirements into supplier contracts and agreements, prioritized by risk, so expectations are enforceable rather than assumed.
Mapping at a glance
GV.SC-05Supply chain requirements in contractsNIST CSF 2.0
RCF-0025Third-party risk managementGovernance & Risk · PolicyRCF-0026Third-party risk managementGovernance & Risk · ProcessRCF-0027Third-party risk managementGovernance & Risk · TechnicalRCF-0331Shared responsibility modelCloud Security · PolicyRCF-0332Shared responsibility modelCloud Security · Process
GV.SC-05 is covered by 9 Sekit CSF controls. +4 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0025Third-party risk management · PolicyRCF-0026Third-party risk management · ProcessRCF-0027Third-party risk management · TechnicalRCF-0331Shared responsibility model · PolicyRCF-0332Shared responsibility model · ProcessRCF-0333Shared responsibility model · TechnicalRCF-0370Cross-border transfers · PolicyRCF-0371Cross-border transfers · ProcessRCF-0372Cross-border transfers · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves GV.SC-05?”
Also via MCP, free with account