control
GV.SC-09 — Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- framework
- nist-csf-2
- type
- preventive
- category
- administrative
Details
- control_id
- GV.SC-09
- framework
- nist-csf-2
- group
- Govern
- domains
- Third-Party / Supply-Chain Risk
- risk_count
- 4
- control_type
- preventive
- control_category
- administrative
- automation
- manual
- key_control
- False
- requirement_status
- Not provided
- requirement_frequency
- Not provided
- source_url
- Not provided
- source_pages
- Not provided
Source
No record-specific source URL is provided.
Connections
- GV.SC-09 — Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle belongs_to NIST CSF 2.0
- UC-TPRM-04 — Monitor vendor performance, services, and risk maps_to GV.SC-09 — Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
- framework
- nist-csf-2
- control_id
- GV.SC-09
- coverage
- partial
- delta
- integration of practices across the technology life cycle satisfied by program control
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.