← NIST CSF 2.0 in plain English

GV.SC-09

Govern / Cybersecurity Supply Chain Risk Management

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle.

Think of it likeNot just buying good roof shingles, but checking every few years that they are still holding up and re-vetting the roofer before the next job.

In plain English

The family keeps checking that the materials and helpers it relies on are still holding up, for as long as it uses them, not just on day one.

Related CIS safeguards (unofficial mapping)