Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.SC-01
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholdersNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.SC-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 2
- laws
- 2
- places
- 0
- with court rulings behind them
- 1
- not yet in force
A law in force is unmarked; the rest wear their state: not yet in force
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months |
Employ cybersecurity professionals who hold a certification the Administration issues or recognizes, ensure the security of the supply chain of the technology products you use, obtain the Administration's security clearance before integrating a new or upgraded information and communication technology system acquired by purchase, donation, development, or any other means, and ensure that any employee or officer with access to your critical assets holds a security clearance from the relevant government body. |
|
| DORA, Articles 28-30 (ICT Third-Party Risk Management) |
Manage ICT third-party risk as an integral, proportionate component of your ICT risk management framework, and, unless you are a microenterprise or an entity covered by Article 16(1), adopt and regularly review a strategy on ICT third-party risk. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.