Sekit CSF · Supply Chain Security · Technical
RCF-0324Ongoing monitoring
Technical tools provide continuous monitoring of supplier security ratings and alert on significant changes
Mapping at a glance
RCF-0324Ongoing monitoringSupply Chain Security · Technical
RCF-0324 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.7Threat intelligencesupportsThis technical control continuously scores supplier external security posture and alerts on drops, an automated form of the threat intelligence this control expects for suppliers.A.5.22Monitoring, review and change management of supplier servicesenablesAutomated services that continuously score supplier security posture and alert on a rating drop are an input that enables A.5.22's ongoing review, feeding it signals rather than performing the review itself.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
DE.CM-06External provider activity monitoredGV.SC-04Suppliers known and prioritizedGV.SC-06Due diligence before engagementGV.SC-07Supplier risk managed over relationship
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Supply Chain Security controls
Ask Sekura: “What evidence proves RCF-0324?”
Also via MCP, free with account