{"version":"0.2.0","built_at":"2026-10-10T20:58:14.188Z","license":"CC BY 4.0 © Mike Reams","canonical":"https://catalog.mikereams.com","capability":{"id":"BC-760.60","name":"Third-Party & Supply Chain Security","level":2,"parent_id":"BC-760","l1_id":"BC-760","industry":"cross-industry","macro_id":"MC-70","path":["Cybersecurity","Third-Party & Supply Chain Security"],"description":"Hold suppliers, partners and the software components the enterprise consumes to a security standard, because an attacker rarely needs to come through the front door.","aliases":["Vendor Security","Supply Chain Risk","Third-Party Risk"],"in_scope":["Supplier security assessment and ongoing monitoring","Third-party access control and offboarding","Software component and dependency integrity","Security terms in supplier agreements"],"out_of_scope":["Commercial supplier performance management (see BC-640)","Procurement sourcing events (see BC-620)"],"csdm_note":null,"status":"active","successor_id":null,"child_ids":["BC-760.60.10","BC-760.60.20","BC-760.60.30"]},"crosswalk":{"realized_by":[{"product_id":"PR-170","product":"GitHub","pc_id":"PC-170.50","pc":"Advanced Security","maturity":"strong","via":null}],"used_in":[],"patterns":[],"stacks":[],"books":[]},"ancestors":[{"id":"BC-760","name":"Cybersecurity","level":1}],"children":[{"id":"BC-760.60.10","name":"Supplier Security Assessment","level":3,"child_count":0},{"id":"BC-760.60.20","name":"Third-Party Access Control","level":3,"child_count":0},{"id":"BC-760.60.30","name":"Software Supply Chain Integrity","level":3,"child_count":0}]}