unified
UC-TPRM-05 — Include suppliers in incident notification and response
Establish agreements or contractual provisions requiring suppliers to notify the organization of security incidents and supply-chain compromises within defined timeframes. Include relevant suppliers and third parties in incident-response planning, exercises, response, and recovery activities, with coordination roles defined in advance.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-TPRM-05
- title
- Include suppliers in incident notification and response
- statement
- Establish agreements or contractual provisions requiring suppliers to notify the organization of security incidents and supply-chain compromises within defined timeframes. Include relevant suppliers and third parties in incident-response planning, exercises, response, and recovery activities, with coordination roles defined in advance.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SR-8
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-08
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-05 — Include suppliers in incident notification and response mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Supplier notification of supply-chain compromises plus pre-planned coordinated response cuts detection and containment time for injected tampered components.
- UC-TPRM-05 — Include suppliers in incident notification and response maps_to GV.SC-08 — Cybersecurity Supply Chain Risk Management: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
- framework
- nist-csf-2
- control_id
- GV.SC-08
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-05 — Include suppliers in incident notification and response maps_to SR-8 — Notification Agreements
- framework
- nist-800-53
- control_id
- SR-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-05 — Include suppliers in incident notification and response mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Supplier incident-notification obligations address the undetected-breach-propagation tail but not the missing-requirements or unmonitored-delivery core, so they contribute to rather than operate the oversight defense.
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-05 — Include suppliers in incident notification and response
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-05 — Include suppliers in incident notification and response
- Third-Party ICT Vendor Regulatory Assurance oversees UC-TPRM-05 — Include suppliers in incident notification and response
- UC-TPRM-05 — Include suppliers in incident notification and response mitigates Critical vendor failure, insolvency or concentration
- strength
- related
- rationale
- Including suppliers in incident response and recovery with pre-defined coordination reduces the impact of an incident-driven prolonged outage.