Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.SC-10
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreementNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.SC-10
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
Sector security regimes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| DORA, Articles 28-30 (ICT Third-Party Risk Management) |
For a contract supporting a critical or important function, add quantitative service level targets, an unrestricted right to monitor, inspect and audit the provider, the provider's cooperation in your threat-led penetration testing, and an exit strategy with a mandatory transition period. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.