Supply Chain Security
What is Supply Chain Security?
Measures to protect the integrity of products and information throughout the supply chain from manufacturing through delivery to end users.
Terms that appear alongside supply chain security
Each of these is named in at least one of the same controls as supply chain security. The number is how many controls name both.
- cybersecurity 15 shared controls
- nist 10 shared controls
- compliance 7 shared controls
- vulnerability 6 shared controls
- audit 6 shared controls
- risk assessment 5 shared controls
- resilience 5 shared controls
- incident response 5 shared controls
Frameworks that govern supply chain security
What the standards actually require on supply chain security
Requirements naming supply chain security across 6 standards, quoted from the control text.
Define the organisation's role, scope, and assets within the supply chain to be secured.
ISO28001-4.1 · Supply chain security context →Maintain inventory of open source and third party components in code using Software Composition Analysis tools.
DS-2 · Ensure software supply chain security →Manage vendor and supply-chain security for ICS components, including integrator and maintenance-provider security, third-party access, and provenance of hardware/software/patches.
CISA-ICS-DID-28 · Vendor Management and Supply Chain Security →Security (Sekyuritii セキュリティ) is the fifth of 10 Principles per Japan AI Guidelines for Business + addresses cybersecurity throughout AI lifecycle including adversarial attacks specific to ML + traditional cyber threats to AI infrastructure.
JP-AIG-Security-Adversarial-Attack-Protection-Prompt-Injection-Data-Poisoning-Model-Extraction-AISI-Red-Team · Japan AI Guidelines Security + Adversarial Attack Protection + Prompt Injection + Data Poisoning + Model Extraction + Membership Inference + AISI Red-Team + MLSecOps + Supply Chain Security + Foundation Model Vulnerabilities →The Directive scopes this deliberately at direct suppliers and service providers, which makes the first artefact an inventory of who those parties are and which of them touch the network and information systems behind the service.
nis2-directive::Art.21.2.d · Supply chain security, covering the relationship with each direct supplier and service provider →Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
NIST-CSF-GV.SC-09 · Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle →Questions people ask about supply chain security
What is Supply Chain Security?
Why is Supply Chain Security important for compliance?
Which compliance frameworks address Supply Chain Security?
Where can I learn more about Supply Chain Security?
See how Supply Chain Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.