SC-1—Policy And Procedures
>Control Description
System and communications protection policies and procedures should address cybersecurity risks throughout the supply chain in relation to the enterprise’s processes, systems, and networks. Enterprise-level and program-specific policies help establish and clarify these requirements, and corresponding procedures provide instructions for meeting these requirements. Policies and procedures should include the coordination of communications among and across multiple enterprise entities within the enterprise, as well as the communications methods, external connections, and processes used between the enterprise and its suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.