{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-02","description":"Before entering a formal relationship, perform security due diligence on prospective vendors and business partners proportionate to their criticality, evaluating security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision. Use acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before contract award.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SR-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-06","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"CC9.2","coverage":"partial","delta":"ongoing monitoring, termination handling, and contractual security/confidentiality commitments satisfied by companion vendor-management and vendor-contract controls","framework":"soc2","relationship":"intersects_with"}],"statement":"Before entering a formal relationship, perform security due diligence on prospective vendors and business partners proportionate to their criticality, evaluating security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision. Use acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before contract award.","title":"Perform risk-based due diligence before engaging vendors","unified_id":"UC-TPRM-02"},"id":"uc:UC-TPRM-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-02","sourceIds":["nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-TPRM-02 — Perform risk-based due diligence before engaging vendors","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:43d7e062ec9a2b5e6cde1456bd143ba1ee5580574be59a579604864e20cafc85","properties":{},"sourceDetailPath":"/data/v1/records/wf-d55-248b03a5.json","sourceId":"wf:D55","targetDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","targetId":"uc:UC-TPRM-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4e73362f2e848fcf1c818a275c33ac071b210bbb27dd47b78dc4b69004fa5ef2","properties":{"rationale":"Due diligence on operational risk and supply-chain exposure screens compliance-risky vendors, reducing downstream vicarious-liability exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57cdbf9575c9e88d566f5d47fe26794420857e2c70bc8c15b2b591ebdfa79ad1","properties":{"rationale":"Acquisition strategies and supply-chain-exposure evaluation before award identify single-source and disruption-prone dependencies early.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-disruption-0d7e0959.json","targetId":"risk:tprm-supply-chain-disruption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6de153c6cee0a29f757335ad6fda4cc627f360bd2027c751ca4af6cd25c5fcb4","properties":{"control_id":"SR-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-5-1d0650c8.json","targetId":"ctrl:nist-800-53:SR-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:733d2d5f37ca5636a2c55417459ef204bce8eb39dae38ceeac518e75ae1cef80","properties":{"rationale":"Acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before award defend against false-front and compromised suppliers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8c220bfd2011cc9dcf6c061c3d3002827fdbc77836a8f7c2ab7418643ccc3e8a","properties":{"rationale":"Evaluating financial and operational risk before engagement screens for insolvency and viability risk, directly reducing critical-vendor-failure likelihood.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:903c9a68d6897c89dfa0bb7681b049684b8e562deb4af17c71a6544d8f58a43b","properties":{},"sourceDetailPath":"/data/v1/records/wf-g28-6078329f.json","sourceId":"wf:G28","targetDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","targetId":"uc:UC-TPRM-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a1922758600bdc17200eb4a0c970ef6e3492d9fffd6777a1a42307c7c742cc06","properties":{"control_id":"GV.SC-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-06-7725080e.json","targetId":"ctrl:nist-csf-2:GV.SC-06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b5b6325a613231fc412f5a9686862687f5807b1b487dc76d4cc9c694998a3484","properties":{"rationale":"Pre-engagement security-posture due diligence screens weaker suppliers at selection but does not itself impose contractual security requirements or ongoing monitoring, so it contributes to rather than operating the oversight defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bcd77ae981664ab460e45d0d9e747a1b7006543721ac2777c0f7b6c1883c2f58","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","targetId":"uc:UC-TPRM-02","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d56d7a17f6d5732e2343735df501f59f10c4f0b0b2ebf4086549e0e839c5744c","properties":{"control_id":"CC9.2","coverage":"partial","delta":"ongoing monitoring, termination handling, and contractual security/confidentiality commitments satisfied by companion vendor-management and vendor-contract controls","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/ctrl-soc2-cc9-2-b2000c2a.json","targetId":"ctrl:soc2:CC9.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d9ebe8969ed3f91ee01f8cf8cc9f3e645a489e9cb80d7c9f765095278a628608","properties":{"rationale":"Evaluating supply-chain exposure and provider concentration before engaging AI providers reduces concentration and compromise exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dabb39ba43e2253e43bf0e00f946794199ef0e0611046aa9b492b6d63d4372f0","properties":{},"sourceDetailPath":"/data/v1/records/wf-d56-387bb72b.json","sourceId":"wf:D56","targetDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","targetId":"uc:UC-TPRM-02","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:db56c3f710400092df18918fea12a99dc0c95061f4eae24cda47936cee07a5ef","properties":{"rationale":"Assessing operational risk before engagement screens out likely non-performers, indirectly reducing later service-delivery failures.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e6b5d6eea9b41b87c3a68139f1374bffc0bc3898a20d7045bf35190642f2e6ab","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","targetId":"uc:UC-TPRM-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f72b9181c772128fabff0bcba0bbf0f14f10bfefba3f18a296786e235eb9279f","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","targetId":"uc:UC-TPRM-02","type":"tests"}],"schemaVersion":1}
