data.gift
  • Datasets

http://cyfun.data.gift/data/requirement_GV_SC_05_3

http://cyfun.data.gift/data/requirement_GV_SC_05_3
Concept

  • http://cyfun.data.gift/data/CyFun2025

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_KeyMeasures

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

    • External link
    • Internal link

  • http://cyfun.data.gift/data/subcategory_GV.SC-05

    • External link
    • Internal link

Properties and relations

Direct links from the subject.

Property Value

type

The subject is an instance of a class.

  • External link
  • Internal link

http://cyfun.data.gift/ontology#Requirement

  • External link
  • Internal link

type

The subject is an instance of a class.

  • External link
  • Internal link

Concept

An idea or notion; a unit of thought.

  • External link
  • Internal link

label

A human-readable name for the subject.

  • External link
  • Internal link

GV.SC-05.3: The organisation shall establish contractual requirements permitting the organisation to review the information/cybersecurity programs implemented by suppliers and third-party partners.

http://cyfun.data.gift/ontology#requirementId

  • External link
  • Internal link

GV.SC-05.3

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_ESSENTIAL_E_p36

  • External link
  • Internal link

has broader

Relates a concept to a concept that is more general in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_GV.SC-05

  • External link
  • Internal link

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that the organisation can assess and verify the information/cybersecurity practices of suppliers and third-party partners through contractual agreements. To achieve this goal: • Information/Cybersecurity Requirements Contracts should define clear information/cybersecurity expectations, including OT-specific controls where relevant. • Audit and Review Rights Agreements should grant the organisation the right to audit, assess, or review the information/cybersecurity programs of suppliers and partners. • Verification Methods Conformance should be verified through self-assessments, third-party certifications, or scheduled security evaluations. • Information Sharing Protocols Contracts should specify what information/cybersecurity-related information must be shared, how often, and through which channels. • Continuous Monitoring Suppliers should regularly report on their information/cybersecurity posture and disclose incidents that could impact operations, especially in OT environments. • Non-Compliance Consequences Contracts should outline consequences for failing to meet information/cybersecurity requirements, such as penalties or contract termination.

note

A general note, for any purpose.

  • External link
  • Internal link

<div><p>The goal of this control is to ensure that the organisation can assess and verify the information/cybersecurity practices of suppliers and third-party partners through contractual agreements. To achieve this goal:</p><ul><li>Information/Cybersecurity Requirements Contracts should define clear information/cybersecurity expectations, including OT-specific controls where relevant.</li><li>Audit and Review Rights Agreements should grant the organisation the right to audit, assess, or review the information/cybersecurity programs of suppliers and partners.</li><li>Verification Methods Conformance should be verified through self-assessments, third-party certifications, or scheduled security evaluations.</li><li>Information Sharing Protocols Contracts should specify what information/cybersecurity-related information must be shared, how often, and through which channels.</li><li>Continuous Monitoring Suppliers should regularly report on their information/cybersecurity posture and disclose incidents that could impact operations, especially in OT environments.</li><li>Non-Compliance Consequences Contracts should outline consequences for failing to meet information/cybersecurity requirements, such as penalties or contract termination.</li></ul></div>

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that the organisation can assess and verify the information/cybersecurity practices of suppliers and third-party partners through contractual agreements. To achieve this goal: - Information/Cybersecurity Requirements Contracts should define clear information/cybersecurity expectations, including OT-specific controls where relevant. - Audit and Review Rights Agreements should grant the organisation the right to audit, assess, or review the information/cybersecurity programs of suppliers and partners. - Verification Methods Conformance should be verified through self-assessments, third-party certifications, or scheduled security evaluations. - Information Sharing Protocols Contracts should specify what information/cybersecurity-related information must be shared, how often, and through which channels. - Continuous Monitoring Suppliers should regularly report on their information/cybersecurity posture and disclose incidents that could impact operations, especially in OT environments. - Non-Compliance Consequences Contracts should outline consequences for failing to meet information/cybersecurity requirements, such as penalties or contract termination.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that the organisation can assess and verify the information/cybersecurity practices of suppliers and third-party partners through contractual agreements. To achieve this goal: - Information/Cybersecurity Requirements Contracts should define clear information/cybersecurity expectations, including OT-specific controls where relevant. - Audit and Review Rights Agreements should grant the organisation the right to audit, assess, or review the information/cybersecurity programs of suppliers and partners. - Verification Methods Conformance should be verified through self-assessments, third-party certifications, or scheduled security evaluations. - Information Sharing Protocols Contracts should specify what information/cybersecurity-related information must be shared, how often, and through which channels. - Continuous Monitoring Suppliers should regularly report on their information/cybersecurity posture and disclose incidents that could impact operations, especially in OT environments. - Non-Compliance Consequences Contracts should outline consequences for failing to meet information/cybersecurity requirements, such as penalties or contract termination.

notation

A notation, also known as classification code, is a string of characters such as "T58.5" or "303.4833" used to uniquely identify a concept within the scope of a given concept scheme.

  • External link
  • Internal link

GV.SC-05.3

alternative label

skos:prefLabel, skos:altLabel and skos:hiddenLabel are pairwise disjoint properties.

  • External link
  • Internal link

Supplier security programme review rights

preferred label

A resource has no more than one value of skos:prefLabel per language tag, and no more than one value of skos:prefLabel without language tag.

  • External link
  • Internal link

The organisation shall establish contractual requirements permitting the organisation to review the information/cybersecurity programs implemented by suppliers and third-party partners.

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_KeyMeasures

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#level

  • External link
  • Internal link

http://cyfun.data.gift/data/level_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#isKeyMeasure

  • External link
  • Internal link

1

triple count

The number of triples associated with the subject.

  • External link
  • Internal link

19

in dataset

Specifies the dataset the subject is part of.

  • External link
  • Internal link

http://data.gift/d/datasets/69E8863AA6CE46D9ACD13109

  • External link
  • Internal link

Resultaten 1 - 21 of 21

References

Inverse links to the subject.

Property Subject

http://cyfun.data.gift/ontology#hasRequirement

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_GV.SC-05

  • External link
  • Internal link

has narrower

Relates a concept to a concept that is more specific in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_GV.SC-05

  • External link
  • Internal link

Resultaten 1 - 1 of 1

© 2024 redpencil.io. All rights reserved.