Sekit CSF · Familia
Supply Chain Security
15 controles en 5 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0319Contractual security clausessin mapeos aúnSecurity requirements are formally included in contracts with all suppliers who handle company data or access systemsRCF-0325Offboarding vendorssin mapeos aúnA formal process governs how supplier relationships are ended and access and data are removedRCF-0322Ongoing monitoringsin mapeos aúnThe company formally monitors the security posture of its key suppliers throughout the relationshipRCF-0328Software supply chain (SBOM)sin mapeos aúnThe company formally tracks the software components it uses to manage risks from third-party codeRCF-0316Vendor due diligencesin mapeos aúnThe company formally assesses the security posture of suppliers and vendors before engaging with them
Proceso
RCF-0320Contractual security clausessin mapeos aúnContractual security obligations are consistently enforced and suppliers are held accountable for non-complianceRCF-0326Offboarding vendorssin mapeos aúnVendor offboarding is consistently completed to ensure all access is revoked and data is returned or destroyedRCF-0323Ongoing monitoringsin mapeos aúnSupplier security is consistently reviewed through periodic assessments and real-time intelligenceRCF-0329Software supply chain (SBOM)sin mapeos aúnSoftware bills of materials are consistently maintained and reviewed for vulnerable or compromised componentsRCF-0317Vendor due diligencesin mapeos aúnSecurity assessments are consistently conducted at onboarding and reviewed periodically throughout the relationship
Técnica
RCF-0321Contractual security clausessin mapeos aúnTechnical tools manage supplier contract obligations and track compliance with contractual security requirementsRCF-0327Offboarding vendorssin mapeos aúnTechnical controls automate the revocation of supplier access and verify that no residual access remainsRCF-0324Ongoing monitoringsin mapeos aúnTechnical tools provide continuous monitoring of supplier security ratings and alert on significant changesRCF-0330Software supply chain (SBOM)sin mapeos aúnTechnical tools generate and analyse software bills of materials and alert when components with known vulnerabilities are detectedRCF-0318Vendor due diligencesin mapeos aúnTechnical tools support automated vendor security questionnaires and integrate threat intelligence on supplier risk
Pregúntale a Sekura: «¿Qué evidencia demuestra Supply Chain Security?»
Conecta tu IA · MCP gratis
https://staging.sekit.ai/api/mcp/crosswalk- En Claude o ChatGPT, añade un conector personalizado y pega esta URL.
- Inicia sesión con tu correo para terminar. Gratis, de solo lectura, sin necesidad de organización.