Suppliers and third-party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process.
The organization shall conduct cyber supply chain risk assessments at least annually or when a change to the organization’s critical systems, operational environment, or supply chain occurs; These assessments shall be documented, and the results disseminated to relevant stakeholders including those responsible for ICT/OT systems.
Guidance
This assessment should identify and prioritize potential negative impacts to the organization from the risks associated with the distributed and interconnected nature of ICT/OT product and service supply chains.
A documented list of all the organization’s suppliers, vendors and partners who may be involved in a major incident shall be established, kept up-to-date and made available online and offline.
Guidance
This list should include suppliers, vendors and partners contact information and the services they provide,so they can be contacted for assistance in the event of an outage or service degradation.