← NIST CSF 2.0 in plain English

GV.SC-03

Govern / Cybersecurity Supply Chain Risk Management

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes.

Think of it likeIncluding service provider reviews in your regular home maintenance checks.

In plain English

When the family sits down to review household risks, are our contractors still trustworthy is one of the standing questions, handled right alongside everything else rather than as an afterthought.

Related CIS safeguards (unofficial mapping)