{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-05","description":"Establish agreements or contractual provisions requiring suppliers to notify the organization of security incidents and supply-chain compromises within defined timeframes. Include relevant suppliers and third parties in incident-response planning, exercises, response, and recovery activities, with coordination roles defined in advance.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SR-8","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-08","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Establish agreements or contractual provisions requiring suppliers to notify the organization of security incidents and supply-chain compromises within defined timeframes. Include relevant suppliers and third parties in incident-response planning, exercises, response, and recovery activities, with coordination roles defined in advance.","title":"Include suppliers in incident notification and response","unified_id":"UC-TPRM-05"},"id":"uc:UC-TPRM-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-05","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-TPRM-05 — Include suppliers in incident notification and response","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0af7cbcc3af62176d9352b1122aa71c17fdd98cc3d7c63eea18c5051b4a245b7","properties":{"rationale":"Supplier notification of supply-chain compromises plus pre-planned coordinated response cuts detection and containment time for injected tampered components.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60e5aeaa14fd18fcdc3f1f654b173a1a38b9d8665fc865be38fcf55ed2398e08","properties":{"control_id":"GV.SC-08","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-08-0bb8f74f.json","targetId":"ctrl:nist-csf-2:GV.SC-08","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:63d54a02fc253bc961895de8a513e0e77ff72990796e4d04d7f451631ed50770","properties":{"control_id":"SR-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-8-0f777d39.json","targetId":"ctrl:nist-800-53:SR-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a008fa82050e6f042e205aa0944f4bd1c147a25b43a494f895520544af11b5cb","properties":{"rationale":"Supplier incident-notification obligations address the undetected-breach-propagation tail but not the missing-requirements or unmonitored-delivery core, so they contribute to rather than operate the oversight defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a04cdd26d54aeabeb2c547851bce1e77e62c73a0ee6e10e80f64ce9c6c191302","properties":{},"sourceDetailPath":"/data/v1/records/wf-g29-6f0c8a46.json","sourceId":"wf:G29","targetDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","targetId":"uc:UC-TPRM-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a162b9741542874aac3683db17059cc4320118b768240f40c50381701b31d69d","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","targetId":"uc:UC-TPRM-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c65489ffc767d71a5ae1a8a67249acca7a5905306cf4866b13edf9783069d300","properties":{},"sourceDetailPath":"/data/v1/records/wf-r6-824a647c.json","sourceId":"wf:R6","targetDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","targetId":"uc:UC-TPRM-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ebe31180cd6a5c287a792f35ab12db6b2cc0ee0913b6b1869d82bd98b2027a25","properties":{"rationale":"Including suppliers in incident response and recovery with pre-defined coordination reduces the impact of an incident-driven prolonged outage.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"}],"schemaVersion":1}
