Supplier-risk FAQ answer and scope
Q: How should teams handle supplier risk under NIST CSF 2.0? A: Treat supplier risk as part of CSF governance. Define supplier scope, criticality, expectations, evidence, monitoring cadence, and escalation before relying on a supplier control assertion.
Q: What should the answer show? A: It should explain what action is required, which source supports it, who owns it, and what evidence proves the current state. CSF 2.0 says it does not prescribe how outcomes should be achieved, and it highlights governance and supply chains as important features of the framework.
- Identify critical suppliers and dependencies.
- Set evidence depth by business impact.
- Review supplier posture when service, threat, or contract conditions change.
Primary NIST source for the CSF Core, Organizational Profiles, Tiers, and the flexible implementation model behind this FAQ answer.
Primary NIST source for cybersecurity supply chain risk management practices.