Sekit CSF · Supply Chain Security · Process
RCF-0326Offboarding vendors
Vendor offboarding is consistently completed to ensure all access is revoked and data is returned or destroyed
Mapping at a glance
RCF-0326Offboarding vendorsSupply Chain Security · Process
A.5.18Access rightsISO/IEC 27001:2022 · Annex A controlsA.5.22Monitoring, review and change management of supplier servicesISO/IEC 27001:2022 · Annex A controlsGV.SC-07Supplier risk managed over relationshipNIST CSF 2.0GV.SC-08Suppliers in incident planningNIST CSF 2.0CE4.1Manage the account lifecycleCyber Essentials
RCF-0326 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.18Access rightssupportsExecuting the vendor exit checklist so no account or API key survives termination is A.5.18's revocation requirement applied to supplier access rights.A.5.22Monitoring, review and change management of supplier servicessupportsExecuting the vendor exit checklist for every ended relationship is the change management A.5.22 requires when a supplier relationship itself changes to termination.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Supply Chain Security controls
Ask Sekura: “What evidence proves RCF-0326?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.