Skip to content
Blueprint Catalog

    ↑↓ move · Enter open · Esc close

    02 — Capability · BC-760.60

    Third-Party & Supply Chain Security

    Hold suppliers, partners and the software components the enterprise consumes to a security standard, because an attacker rarely needs to come through the front door.

    • Vendor Security
    • Supply Chain Risk
    • Third-Party Risk

    In scope

    • Supplier security assessment and ongoing monitoring
    • Third-party access control and offboarding
    • Software component and dependency integrity
    • Security terms in supplier agreements

    Out of scope

    • Commercial supplier performance management (see BC-640)
    • Procurement sourcing events (see BC-620)

    Realized by · 1

    Used in · 0

    • Not yet placed on a value stream.

    Build it · 0

    • Nothing in the library points here yet.

    Decomposes into · 3