graphgrc

SCF - TPM-02 - Third-Party Criticality Assessments

Mechanisms exist to identify, prioritize and assess suppliers and partners of critical systems, components and services using a supply chain risk assessment process relative to their importance in supporting the delivery of high-value services.

Mapped framework controls

ISO 27002

NIST 800-53

SOC 2

Control questions

Does the organization identify, prioritize and assess suppliers and partners of critical systems, components and services using a supply chain risk assessment process relative to their importance in supporting the delivery of high-value services?