
SCF - TPM-05.1 - Security Compromise Notification Agreements

Mechanisms exist to compel External Service Providers (ESPs) to provide notification of actual or potential compromises in the supply chain that can potentially affect or have adversely affected systems, applications and/or services that the organization utilizes.

Mapped framework controls

ISO 27002

NIST 800-53

Control questions

Does the organization compel External Service Providers (ESPs) to provide notification of actual or potential compromises in the supply chain that can potentially affect or have adversely affected systems, applications and/or services that the organization utilizes?