data.gift
  • Datasets

http://cyfun.data.gift/data/requirement_GV_SC_07_1

http://cyfun.data.gift/data/requirement_GV_SC_07_1
Concept

  • http://cyfun.data.gift/data/CyFun2025

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_delta_BASIC_to_IMPORTANT

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_IMPORTANT

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

    • External link
    • Internal link

  • http://cyfun.data.gift/data/subcategory_GV.SC-07

    • External link
    • Internal link

Properties and relations

Direct links from the subject.

Property Value

type

The subject is an instance of a class.

  • External link
  • Internal link

http://cyfun.data.gift/ontology#Requirement

  • External link
  • Internal link

type

The subject is an instance of a class.

  • External link
  • Internal link

Concept

An idea or notion; a unit of thought.

  • External link
  • Internal link

label

A human-readable name for the subject.

  • External link
  • Internal link

GV.SC-07.1: The risks posed by a supplier, its products and services and other third parties shall be identified, documented, prioritised, mitigated and assessed at least annually and when changes occur during the relationship.

http://cyfun.data.gift/ontology#requirementId

  • External link
  • Internal link

GV.SC-07.1

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_ESSENTIAL_E_p37

  • External link
  • Internal link

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_IMPORTANT_E_p27

  • External link
  • Internal link

has broader

Relates a concept to a concept that is more general in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_GV.SC-07

  • External link
  • Internal link

note

A general note, for any purpose.

  • External link
  • Internal link

<div><p>The goal of this control is to ensure that risks related to suppliers, their products and services, and other third parties are continuously identified, assessed, prioritised, and managed throughout the relationship, especially when changes occur in critical systems. To achieve this goal:</p><ul><li>Tailored Risk Assessments Assessment formats and frequencies should be adapted based on the supplier’s reputation and the criticality of the products or services provided, including OT components.</li><li>Broader Risk Considerations Risk evaluations should include potential service disruptions and concentration risks that could impact operations or OT environments.</li><li>Evidence of Compliance Suppliers should provide evidence of compliance with contractual cybersecurity requirements, such as self- assessments (e.g. CyFun®), certifications, warranties, test results, labels, or third-party audit reports.</li><li>Ongoing Monitoring Critical suppliers should be monitored throughout the relationship using inspections, audits, tests, or other evaluation methods to ensure security obligations remain fulfilled.</li><li>Risk Profile Updates Changes in supplier services, products, or performance should trigger a reassessment of their risk profile and criticality, especially when OT systems are involved.</li><li>Business Continuity Planning An action plan should be in place to address unexpected supplier disruptions and maintain operational continuity.</li></ul></div>

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that risks related to suppliers, their products and services, and other third parties are continuously identified, assessed, prioritised, and managed throughout the relationship, especially when changes occur in critical systems. To achieve this goal: • Tailored Risk Assessments Assessment formats and frequencies should be adapted based on the supplier’s reputation and the criticality of the products or services provided, including OT components. • Broader Risk Considerations Risk evaluations should include potential service disruptions and concentration risks that could impact operations or OT environments. • Evidence of Compliance Suppliers should provide evidence of compliance with contractual cybersecurity requirements, such as self- assessments (e.g. CyFun®), certifications, warranties, test results, labels, or third-party audit reports. • Ongoing Monitoring Critical suppliers should be monitored throughout the relationship using inspections, audits, tests, or other evaluation methods to ensure security obligations remain fulfilled. • Risk Profile Updates Changes in supplier services, products, or performance should trigger a reassessment of their risk profile and criticality, especially when OT systems are involved. • Business Continuity Planning An action plan should be in place to address unexpected supplier disruptions and maintain operational continuity.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that risks related to suppliers, their products and services, and other third parties are continuously identified, assessed, prioritised, and managed throughout the relationship, especially when changes occur in critical systems. To achieve this goal: - Tailored Risk Assessments Assessment formats and frequencies should be adapted based on the supplier’s reputation and the criticality of the products or services provided, including OT components. - Broader Risk Considerations Risk evaluations should include potential service disruptions and concentration risks that could impact operations or OT environments. - Evidence of Compliance Suppliers should provide evidence of compliance with contractual cybersecurity requirements, such as self- assessments (e.g. CyFun®), certifications, warranties, test results, labels, or third-party audit reports. - Ongoing Monitoring Critical suppliers should be monitored throughout the relationship using inspections, audits, tests, or other evaluation methods to ensure security obligations remain fulfilled. - Risk Profile Updates Changes in supplier services, products, or performance should trigger a reassessment of their risk profile and criticality, especially when OT systems are involved. - Business Continuity Planning An action plan should be in place to address unexpected supplier disruptions and maintain operational continuity.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to ensure that risks related to suppliers, their products and services, and other third parties are continuously identified, assessed, prioritised, and managed throughout the relationship, especially when changes occur in critical systems. To achieve this goal: - Tailored Risk Assessments Assessment formats and frequencies should be adapted based on the supplier’s reputation and the criticality of the products or services provided, including OT components. - Broader Risk Considerations Risk evaluations should include potential service disruptions and concentration risks that could impact operations or OT environments. - Evidence of Compliance Suppliers should provide evidence of compliance with contractual cybersecurity requirements, such as self- assessments (e.g. CyFun®), certifications, warranties, test results, labels, or third-party audit reports. - Ongoing Monitoring Critical suppliers should be monitored throughout the relationship using inspections, audits, tests, or other evaluation methods to ensure security obligations remain fulfilled. - Risk Profile Updates Changes in supplier services, products, or performance should trigger a reassessment of their risk profile and criticality, especially when OT systems are involved. - Business Continuity Planning An action plan should be in place to address unexpected supplier disruptions and maintain operational continuity.

notation

A notation, also known as classification code, is a string of characters such as "T58.5" or "303.4833" used to uniquely identify a concept within the scope of a given concept scheme.

  • External link
  • Internal link

GV.SC-07.1

alternative label

skos:prefLabel, skos:altLabel and skos:hiddenLabel are pairwise disjoint properties.

  • External link
  • Internal link

Supplier risk assessment

preferred label

A resource has no more than one value of skos:prefLabel per language tag, and no more than one value of skos:prefLabel without language tag.

  • External link
  • Internal link

The risks posed by a supplier, its products and services and other third parties shall be identified, documented, prioritised, mitigated and assessed at least annually and when changes occur during the relationship.

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_delta_BASIC_to_IMPORTANT

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_IMPORTANT

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#level

  • External link
  • Internal link

http://cyfun.data.gift/data/level_IMPORTANT

  • External link
  • Internal link

triple count

The number of triples associated with the subject.

  • External link
  • Internal link

19

in dataset

Specifies the dataset the subject is part of.

  • External link
  • Internal link

http://data.gift/d/datasets/69E8863AA6CE46D9ACD13109

  • External link
  • Internal link

Resultaten 1 - 21 of 21

References

Inverse links to the subject.

Property Subject

http://cyfun.data.gift/ontology#hasRequirement

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_GV.SC-07

  • External link
  • Internal link

has narrower

Relates a concept to a concept that is more specific in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_GV.SC-07

  • External link
  • Internal link

Resultaten 1 - 1 of 1

© 2024 redpencil.io. All rights reserved.