GV.SC-08: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
Subcategory is new to this version of the framework and incorporates the following item from the previous version: ID.SC-5: Response and recovery planning and testing are conducted with suppliers and third-party providers.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
Ex1: Define and use rules and protocols for reporting incident response and recovery activities and the status between the organization and its suppliers
Ex2: Identify and document the roles and responsibilities of the organization and its suppliers for incident response
Ex3: Include critical suppliers in incident response exercises and simulations
Ex4: Define and coordinate crisis communication methods and protocols between the organization and its critical suppliers
Ex5: Conduct collaborative lessons learned sessions with critical suppliers
3rd: 3rd Party Risk
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
CP-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] contingency planning policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…
IR-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] incident response policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…
SA-4: Acquisition Process
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [Assignment (one or more): standardized contract language, [Assignment: organization-defined contract language] ] in the acquisition contract for the system, system component, or system service: Security and privacy functional requirements; Strength of mechanism requirements; Security and privacy assurance requirements; Controls needed to satisfy the…
SA-9: External System Services
Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: [Assignment: organization-defined controls]; Define and document organizational oversight and user roles and responsibilities with regard to external system services; and Employ the following processes, methods, and techniques to monitor control compliance by external service providers on…
SR-2: Supply Chain Risk Management Plan
Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the following systems, system components or system services: [Assignment: organization-defined systems, system components, or system services]; Review and update the supply chain risk management plan [Assignment: organization-defined frequency] or as…
SR-3: Supply Chain Controls and Processes
Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Assignment: organization-defined system or system component] in coordination with [Assignment: organization-defined supply chain personnel]; Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit…
SR-8: Notification Agreements
Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [Assignment (one or more): notification of supply chain compromises, [Assignment: organization-defined results of assessments or audits] ].
NIST SP 800-171 Revision 3.0
03.06.01: Incident Handling
Implement an incident-handling capability that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery.
03.06.02: Incident Monitoring, Reporting, and Response Assistance
Track and document system security incidents. Report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period]. Report incident information to [Assignment: organization-defined authorities]. Provide an incident response support resource that offers advice and assistance to system users on handling and reporting incidents.
03.06.05: Incident Response Plan
Develop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability, Describes the structure and organization of the incident response capability, Provides a high-level approach for how the incident response capability fits into the overall organization, Defines reportable incidents, Addresses the sharing of incident information, and Designates responsibilities…
03.15.01: Policy and Procedures
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for the protection of CUI. Review and update policies and procedures [Assignment: organization-defined frequency].
03.16.03: External System Services
Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security requirements: [Assignment: organization-defined security requirements]. Define and document user roles and responsibilities with regard to external system services, including shared responsibilities with external service providers. Implement processes, methods, and techniques to monitor security…
03.17.01: Supply Chain Risk Management Plan
Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of the system, system components, or system services. Review and update the supply chain risk management plan [Assignment: organization-defined frequency]. Protect the supply chain risk management plan from unauthorized disclosure.
03.17.03: Supply Chain Requirements and Processes
Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes. Enforce the following security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events: [Assignment: organization-defined security requirements].
Cloud Controls Matrix v4.0
BCR-06: Business Continuity Exercises
Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.
BCR-07: Communication
Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.
DSP-18: Disclosure Notification
The CSP must have in place, and describe to CSCs the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations. The CSP must give special attention to the notification procedure to interested CSCs, unless otherwise prohibited, such as a prohibition under criminal…
SEF-03: Incident Response Plans
Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: relevant internal departments, impacted CSCs, and other business critical relationships (such as supply-chain) that may be impacted.
SEF-04: Incident Response Testing
Test and update as necessary incident response plans at planned intervals or upon significant organizational or environmental changes for effectiveness.
SEF-07: Security Breach Notification
Define and implement, processes, procedures and technical measures for security breach notifications. Report security breaches and assumed security breaches including any relevant supply chain breaches, as per applicable SLAs, laws and regulations.
UEM-14: Third-Party Endpoint Security Posture
Define, implement and evaluate processes, procedures and technical and/or contractual measures to maintain proper security of third-party endpoints with access to organizational assets.
Critical Security Controls Version 8.1
15.4: Ensure Service Provider Contracts Include Security Requirements
Ensure service provider contracts include security requirements. Example requirements may include minimum security program requirements, security incident and/or data breach notification and response, data encryption requirements, and data disposal commitments. These security requirements must be consistent with the enterprise's service provider management policy. Review service provider contracts annually to ensure contracts are not missing security requirements.