|
controlSR-6
Supplier Assessments and Reviews (SR-6)
Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide [organization-defined].
Security Baselines
MODERATEHIGHLOW
supply-chainacquisitionthird-partyrisk
Why These Connect
Maps To25
These are equivalent or closely aligned requirements in other frameworks.
Baselined In2
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports26
These related controls work together — a change to one may affect the others.
Enhances1
These enhancements add specific capabilities or refinements to the base control.
Related Controls(13)
AT-3Role-based Training (AT-3)
LMH
CA-7Continuous Monitoring (CA-7)LMH
CA-8Penetration Testing (CA-8)H
PE-16Delivery and Removal (PE-16)LMH
PM-30Supply Chain Risk Management Strategy (PM-30)SA-10Developer Configuration Management (SA-10)MH
SA-11Developer Testing and Evaluation (SA-11)MH
SA-15Development Process, Standards, and Tools (SA-15)MH
SA-21Developer Screening (SA-21)H
SA-24Design For Cyber Resiliency (SA-24)SI-7Software, Firmware, and Information Integrity (SI-7)MH
SR-3Supply Chain Controls and Processes (SR-3)LMH
SR-5Acquisition Strategies, Tools, and Methods (SR-5)LMH
Cross-Framework Mappings(25)
GV.OC-02GV.OC-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-01GV.OV-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-02GV.OV-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-03GV.OV-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-04GV.SC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-05GV.SC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-06GV.SC-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-07GV.SC-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-09GV.SC-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-10GV.SC-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-10ID.RA-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
GV.OC-02GV.OC-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-01GV.OV-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-02GV.OV-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-03GV.OV-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-04GV.SC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-05GV.SC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-06GV.SC-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-07GV.SC-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-09GV.SC-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-10GV.SC-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-10ID.RA-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5