Sekit CSF · Family
Supply Chain Security
15 controls in 5 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0319Contractual security clausesno mappings yetSecurity requirements are formally included in contracts with all suppliers who handle company data or access systemsRCF-0325Offboarding vendorsno mappings yetA formal process governs how supplier relationships are ended and access and data are removedRCF-0322Ongoing monitoringno mappings yetThe company formally monitors the security posture of its key suppliers throughout the relationshipRCF-0328Software supply chain (SBOM)no mappings yetThe company formally tracks the software components it uses to manage risks from third-party codeRCF-0316Vendor due diligenceno mappings yetThe company formally assesses the security posture of suppliers and vendors before engaging with them
Process
RCF-0320Contractual security clausesno mappings yetContractual security obligations are consistently enforced and suppliers are held accountable for non-complianceRCF-0326Offboarding vendorsno mappings yetVendor offboarding is consistently completed to ensure all access is revoked and data is returned or destroyedRCF-0323Ongoing monitoringno mappings yetSupplier security is consistently reviewed through periodic assessments and real-time intelligenceRCF-0329Software supply chain (SBOM)no mappings yetSoftware bills of materials are consistently maintained and reviewed for vulnerable or compromised componentsRCF-0317Vendor due diligenceno mappings yetSecurity assessments are consistently conducted at onboarding and reviewed periodically throughout the relationship
Technical
RCF-0321Contractual security clausesno mappings yetTechnical tools manage supplier contract obligations and track compliance with contractual security requirementsRCF-0327Offboarding vendorsno mappings yetTechnical controls automate the revocation of supplier access and verify that no residual access remainsRCF-0324Ongoing monitoringno mappings yetTechnical tools provide continuous monitoring of supplier security ratings and alert on significant changesRCF-0330Software supply chain (SBOM)no mappings yetTechnical tools generate and analyse software bills of materials and alert when components with known vulnerabilities are detectedRCF-0318Vendor due diligenceno mappings yetTechnical tools support automated vendor security questionnaires and integrate threat intelligence on supplier risk
Ask Sekura: “What evidence proves Supply Chain Security?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.