Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.SC-10

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreementNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.SC-10

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

1
law
1
place
0
with court rulings behind them
0
not yet in force

Sector security regimes

1 law, 1 place
PlaceLawWhat it asks, as read here
European Union DORA, Articles 28-30 (ICT Third-Party Risk Management)

For a contract supporting a critical or important function, add quantitative service level targets, an unrestricted right to monitor, inspect and audit the provider, the provider's cooperation in your threat-led penetration testing, and an exit strategy with a mandatory transition period.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.