unified
UC-ASSET-05 — Inventory supplier services and assess critical suppliers
Maintain an inventory of services provided by suppliers, including the systems and data each service touches and the internal owner of the relationship. Assess critical suppliers for security and risk before acquisition or engagement, record the results, and reassess when services, dependencies, or risk profiles change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Asset Management & Inventory
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-ASSET-05
- title
- Inventory supplier services and assess critical suppliers
- statement
- Maintain an inventory of services provided by suppliers, including the systems and data each service touches and the internal owner of the relationship. Assess critical suppliers for security and risk before acquisition or engagement, record the results, and reassess when services, dependencies, or risk profiles change.
- domain
- Asset Management & Inventory
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- ID.AM-04
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.RA-10
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ASSET-05 — Inventory supplier services and assess critical suppliers maps_to ID.RA-10 — Risk Assessment: Critical suppliers are assessed prior to acquisition
- framework
- nist-csf-2
- control_id
- ID.RA-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-05 — Inventory supplier services and assess critical suppliers mitigates Undocumented data inventory and unmapped data flows
- strength
- related
- rationale
- Supplier-service inventory records only the processor/sub-processor leg, a partial contribution; the authoritative data inventory, RoPA, and flow diagrams (UC-02) are the operative defense for this privacy risk.
- Third-Party ICT Vendor Regulatory Assurance oversees UC-ASSET-05 — Inventory supplier services and assess critical suppliers
- Supplier Service Registry & Critical Supplier Assessment operates UC-ASSET-05 — Inventory supplier services and assess critical suppliers
- Third-Party Vendor Risk Lifecycle oversees UC-ASSET-05 — Inventory supplier services and assess critical suppliers
- UC-ASSET-05 — Inventory supplier services and assess critical suppliers mitigates Incomplete asset inventory and classification
- strength
- related
- rationale
- Supplier-service inventory with named internal owners extends asset accountability to third-party services.
- UC-ASSET-05 — Inventory supplier services and assess critical suppliers maps_to ID.AM-04 — Asset Management: Inventories of services provided by suppliers are maintained
- framework
- nist-csf-2
- control_id
- ID.AM-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.