Assessing your own suppliers: the clause the question tests
Whether the supplier selects its own suppliers with care and keeps them overseen during the relationship.
How the customer usually asks it
example"How do you assess the security of your own critical suppliers?"
Anchor clauses
5 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.22 Monitoring, review and change management of supplier services |
| SOC 2 (Trust Services Criteria) | CC9.2 Risk mitigation activities include assessment of vendor and business partner controls |
| SIG (Shared Assessments) | domain T Supply Chain Risk Management |
| NIST Cybersecurity Framework 2.0 | GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship |
| NIST SP 800-53 Rev 5 | SR-6 Supplier assessments and reviews |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The supplier assessment procedure, the tiering of suppliers by the data they reach, and the last assessment record for each critical supplier.
The clauses, with what an assessor asks for
ISO 27001 5.22 Monitoring, review and change management of supplier servicesRegularly monitor, review and manage change in supplier security practice and service delivery.
Where answers usually fall short: Relying on informal verbal updates; Missing documented approval for supplier changes
Source: ISO/IEC 27001:2022
SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controlsNamed, not quoted: the criteria text is not held in full here.
Where answers usually fall short: Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs; Inventory covering vendors known to procurement, missing services engaged directly by teams
Source: SOC 2 (Trust Services Criteria)
SIG domain T Supply Chain Risk ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Manage risk across the supply chain including subservice organizations, fourth parties, hardware and software providers, and concentration risk, with appropriate due diligence and continuous monitoring.
Where answers usually fall short: No fourth party visibility; Continuous monitoring not actioned
Source: SIG (Shared Assessments)
NIST CSF GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationshipThe risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Where answers usually fall short: Continuous monitoring only via marketing dashboards; Reassessments slip beyond cycle
Source: NIST Cybersecurity Framework 2.0
SP 800-53 SR-6 Supplier assessments and reviewsRequires assessment and review, at an organization-defined frequency, of the supply chain risk attached to each supplier or contractor and to the particular system, component or service they deliver.
Where answers usually fall short: Assessment performed at onboarding only with no defined review cadence; Assessment covers the supplier's corporate posture but not the specific component supplied
Source: NIST SP 800-53 Rev 5