← NIST CSF 2.0 in plain English

GV.SC-01

Govern / Cybersecurity Supply Chain Risk Management

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders.

Think of it likeWriting down the family's whole approach to outside help before calling anyone: how you vet them, what you require, and who gives the final yes.

In plain English

Before hiring anyone, the family has already agreed on its rules for choosing and dealing with outside helpers.

Related CIS safeguards (unofficial mapping)