Sekit CSF · Governance & Risk · Policy
RCF-0025Third-party risk management
Third party suppliers and vendors are formally assessed for security risk
Mapping at a glance
RCF-0025Third-party risk managementGovernance & Risk · Policy
A.5.19Information security in supplier relationshipsISO/IEC 27001:2022 · Annex A controlsGV.SC-01Supply chain risk program establishedNIST CSF 2.0GV.SC-02Supplier roles and responsibilities establishedNIST CSF 2.0GV.SC-03Supply chain risk integratedNIST CSF 2.0GV.SC-04Suppliers known and prioritizedNIST CSF 2.0
RCF-0025 maps to 11 controls across the published frameworks. +6 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.SC-01Supply chain risk program establishedGV.SC-02Supplier roles and responsibilities establishedGV.SC-03Supply chain risk integratedGV.SC-04Suppliers known and prioritizedGV.SC-05Supply chain requirements in contractsGV.SC-06Due diligence before engagementGV.SC-07Supplier risk managed over relationshipGV.SC-08Suppliers in incident planningGV.SC-09Supply chain practices integrated in lifecycle
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0025?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.