Sekit CSF · Governance & Risk · Process
RCF-0026Third-party risk management
Third party security requirements are consistently enforced through contracts
Mapping at a glance
RCF-0026Third-party risk managementGovernance & Risk · Process
A.5.20Addressing information security within supplier agreementsISO/IEC 27001:2022A.5.21Managing information security in the ICT supply chainISO/IEC 27001:2022A.5.22Monitoring, review and change management of supplier servicesISO/IEC 27001:2022GV.SC-01Supply chain risk program establishedNIST CSF 2.0GV.SC-02Supplier roles and responsibilities establishedNIST CSF 2.0
RCF-0026 maps to 13 controls across the published frameworks. +8 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.20Addressing information security within supplier agreementsequivalentEmbedding breach notification, data protection terms and audit rights into supplier contracts, then verifying them at signing and renewal, is A.5.20's requirement carried out step by step.A.5.21Managing information security in the ICT supply chainsupportsEmbedding breach notification and assessment rights into supplier contracts extends risk management down the technology supply chain, A.5.21's specific concern beyond the direct supplier relationship.A.5.22Monitoring, review and change management of supplier servicessupportsVerifying contractual obligations at signing and renewal is a checkpoint that feeds A.5.22's ongoing review of whether suppliers still meet what was agreed.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.SC-01Supply chain risk program establishedGV.SC-02Supplier roles and responsibilities establishedGV.SC-03Supply chain risk integratedGV.SC-04Suppliers known and prioritizedGV.SC-05Supply chain requirements in contractsGV.SC-06Due diligence before engagementGV.SC-07Supplier risk managed over relationshipGV.SC-08Suppliers in incident planningGV.SC-09Supply chain practices integrated in lifecycle
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
This topic through the other lenses
All Governance & Risk controls
Ask Sekura: “What evidence proves RCF-0026?”
Also via MCP, free with account