graphgrc

SCF - IRO-10.4 - Supply Chain Coordination

Mechanisms exist to provide cybersecurity & data privacy incident information to the provider of the product or service and other organizations involved in the supply chain for systems or system components related to the incident.

Mapped framework controls

ISO 27002

NIST 800-53

SOC 2

Control questions

Does the organization provide cybersecurity & data privacy incident information to the provider of the product or service and other organizations involved in the supply chain for systems or system components related to the incident?