TPM-03—Supply Chain Risk Management (SCRM)
Weight: 9
>Control Description
Mechanisms exist to:
(1) Evaluate security risks and threats associated with Technology Assets, Applications and/or Services (TAAS) supply chains; and
(2) Take appropriate remediation actions to minimize the organization's exposure to those risks and threats, as necessary.
>Cross-Framework Mappings
Canada ITSP 10.171
EU Cyber Resilience Act
EU DORA
SOC 2 TSC (Detailed)
NIST SP 800-171 Rev 3
GLBA (16 CFR 314)
SEC Cybersecurity Rule
Ask AI
Configure your API key to use AI features.