logo

Meeting the Third-Party Risk Requirements of NIST CSF in 2024 | UpGuard

ID: 6fcbd5e9-95f5-5c8e-9184-8465908b8986

STIX ID: report--6fcbd5e9-95f5-5c8e-9184-8465908b8986

Feed Name: UpGuard Blog

Date Published: 2024-01-19

Date Updated: 2026-05-01

...
...

**NIST Cybersecurity Framework (CSF) 2.0** overview emphasizing the new **Govern (GV)** function and its **Cybersecurity Supply Chain Risk Management (GV.SC-01–GV.SC-10)** subcategories, clarifying that CSF is mandatory for U.S. federal entities and their supply chains but optional elsewhere, and mapping practical third‑party risk measures—attack surface monitoring, vendor tiering, security assessments/questionnaires, security ratings, and regular pen‑test reporting—to GV.SC requirements to strengthen vendor risk management and supply chain resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.