Sekit CSF · Familia
Supply Chain Security
15 controles en 5 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0319Contractual security clauses7 mapeosSecurity requirements are formally included in contracts with all suppliers who handle company data or access systemsRCF-0325Offboarding vendors5 mapeosA formal process governs how supplier relationships are ended and access and data are removedRCF-0322Ongoing monitoring7 mapeosThe company formally monitors the security posture of its key suppliers throughout the relationshipRCF-0328Software supply chain (SBOM)6 mapeosThe company formally tracks the software components it uses to manage risks from third-party codeRCF-0316Vendor due diligence8 mapeosThe company formally assesses the security posture of suppliers and vendors before engaging with them
Proceso
RCF-0320Contractual security clauses6 mapeosContractual security obligations are consistently enforced and suppliers are held accountable for non-complianceRCF-0326Offboarding vendors5 mapeosVendor offboarding is consistently completed to ensure all access is revoked and data is returned or destroyedRCF-0323Ongoing monitoring7 mapeosSupplier security is consistently reviewed through periodic assessments and real-time intelligenceRCF-0329Software supply chain (SBOM)7 mapeosSoftware bills of materials are consistently maintained and reviewed for vulnerable or compromised componentsRCF-0317Vendor due diligence7 mapeosSecurity assessments are consistently conducted at onboarding and reviewed periodically throughout the relationship
Técnica
RCF-0321Contractual security clauses5 mapeosTechnical tools manage supplier contract obligations and track compliance with contractual security requirementsRCF-0327Offboarding vendors5 mapeosTechnical controls automate the revocation of supplier access and verify that no residual access remainsRCF-0324Ongoing monitoring6 mapeosTechnical tools provide continuous monitoring of supplier security ratings and alert on significant changesRCF-0330Software supply chain (SBOM)6 mapeosTechnical tools generate and analyse software bills of materials and alert when components with known vulnerabilities are detectedRCF-0318Vendor due diligence6 mapeosTechnical tools support automated vendor security questionnaires and integrate threat intelligence on supplier risk
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en ISO/IEC 42001:2023 — Annex A
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra Supply Chain Security?»
También vía MCP, gratis con cuenta