Skip to content

Latest commit

 

History

History
18 lines (14 loc) · 921 Bytes

rsk-09-supplychainriskmanagementscrmplan.md

File metadata and controls

18 lines (14 loc) · 921 Bytes

SCF - RSK-09 - Supply Chain Risk Management (SCRM) Plan

Mechanisms exist to develop a plan for Supply Chain Risk Management (SCRM) associated with the development, acquisition, maintenance and disposal of systems, system components and services, including documenting selected mitigating actions and monitoring performance against those plans.

Mapped framework controls

ISO 27002

NIST 800-53

SOC 2

Control questions

Does the organization develop a plan for Supply Chain Risk Management (SCRM) associated with the development, acquisition, maintenance and disposal of systems, system components and services, including documenting selected mitigating actions and monitoring performance against those plans?