unified

UC-TPRM-02 — Perform risk-based due diligence before engaging vendors

Before entering a formal relationship, perform security due diligence on prospective vendors and business partners proportionate to their criticality, evaluating security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision. Use acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before contract award.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Third-Party / Supply-Chain Risk
type
preventive
category
administrative

Details

unified_id
UC-TPRM-02
title
Perform risk-based due diligence before engaging vendors
statement
Before entering a formal relationship, perform security due diligence on prospective vendors and business partners proportionate to their criticality, evaluating security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision. Use acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before contract award.
domain
Third-Party / Supply-Chain Risk
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    SR-5
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.SC-06
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC9.2
    coverage
    partial
    delta
    ongoing monitoring, termination handling, and contractual security/confidentiality commitments satisfied by companion vendor-management and vendor-contract controls
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections