02 — Capability · BC-760.60
Third-Party & Supply Chain Security
Hold suppliers, partners and the software components the enterprise consumes to a security standard, because an attacker rarely needs to come through the front door.
- Vendor Security
- Supply Chain Risk
- Third-Party Risk
In scope
- Supplier security assessment and ongoing monitoring
- Third-party access control and offboarding
- Software component and dependency integrity
- Security terms in supplier agreements
Out of scope
- Commercial supplier performance management (see BC-640)
- Procurement sourcing events (see BC-620)
Realized by · 1
Used in · 0
- Not yet placed on a value stream.
Build it · 0
- Nothing in the library points here yet.
Decomposes into · 3
- BC-760.60.10Supplier Security AssessmentAssess suppliers before onboarding and on a cycle afterward, proportionate to the data and access each one has.
- BC-760.60.20Third-Party Access ControlGrant external parties the narrowest access that lets them do their job, monitor it and remove it the day the engagement ends.
- BC-760.60.30Software Supply Chain IntegrityKnow what open-source and commercial components run in the estate, verify their provenance and respond when one is found to be compromised.