Every framework tells you to manage third-party risk; none of them hand you a template. This series takes the supply-chain requirement in each major regime, NIS2 Article 21(2)(d), the DORA Register of Information, ISO 27001 A.5.19–A.5.23, NIST CSF GV.SC, and CIS Control 15, and turns it into the same practical object: a supplier register you can defend, with criticality tiering, contractual flow-down, and the evidence an assessor or supervisor actually samples. Read one for your framework, or read across them to see where they agree.
5 posts in this topic
CIS Control 15: Service Provider Management, IG1 to IG3 in Practice
Implementing CIS Controls v8.1 Control 15 Service Provider Management: the seven safeguards in IG1 to IG3 order, building the 15.1 inventory, and the…
The DORA Register of Information: Structure, Common Failures & What Supervisors Check
Build a DORA Register of Information that passes the ESA collection: the ITS template structure, LEI and critical-function pitfalls, and what supervisors…
ISO 27001:2022 Supplier Relationships: A.5.19–A.5.23 in Practice
Implementing ISO/IEC 27001:2022 supplier controls A.5.19 to A.5.23: the supplier register, agreements, ICT supply chain, monitoring, and cloud, with the…
NIS2 Supply Chain Security: Building a Supplier Register With No Template
NIS2 Article 21(2)(d) supply chain security without a prescribed format: how to build a defensible supplier register, tier by criticality, and evidence it…
NIST CSF 2.0 GV.SC: Supply Chain Risk Management as a Govern Outcome
Implementing NIST CSF 2.0 GV.SC: the ten C-SCRM subcategories, a prioritized supplier inventory, and using Current and Target Profiles to drive third-party…