Under active development Content is continuously updated and improved

SC-1Policy And Procedures

>Control Description

System and communications protection policies and procedures should address cybersecurity risks throughout the supply chain in relation to the enterprise’s processes, systems, and networks. Enterprise-level and program-specific policies help establish and clarify these requirements, and corresponding procedures provide instructions for meeting these requirements. Policies and procedures should include the coordination of communications among and across multiple enterprise entities within the enterprise, as well as the communications methods, external connections, and processes used between the enterprise and its suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.