| name | ID.SC-03_idsc-03 |
| description | Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe |
| category | information-gathering |
| version | 2.0 |
| author | cyberstrike-official |
| tags | ["nist","csf","v2.0","id-sc-03","id","subcategory"] |
| tech_stack | ["aws","azure","gcp","network"] |
| cwe_ids | ["CWE-200"] |
| chains_with | [] |
| prerequisites | ["Supply Chain Risk Management (ID.SC)"] |
| severity_boost | {} |
ID.SC-03 ID.SC-03
Subcategory of: Supply Chain Risk Management (ID.SC)
High-Level Description
Function: IDENTIFY (ID)
Framework: NIST Cybersecurity Framework v2.0
Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybersecurity program and Cyber Supply Chain Risk Management Plan.
What to Check
How to Test
Step 1: Identify Current Profile
Determine the organization's current and target CSF profile tier for ID.SC-03.
Step 2: Assess Outcome Achievement
# Review organizational policies and procedures
# Check for evidence that ID.SC-03 outcome is met
# Interview stakeholders responsible for IDENTIFY
Step 3: Map to Technical Controls
Identify which SP 800-53 controls implement this CSF outcome and verify their operating effectiveness.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Assess cloud security posture | cloud_audit_* tools |
| Manual Review | Policy and procedure review | Interviews and documentation |
Remediation Guide
Achieve the ID.SC-03 ID.SC-03 outcome:
Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybersecurity program and Cyber Supply Chain Risk Management Plan.
Risk Assessment
| Finding | Severity | Impact |
|---|
| ID.SC-03 ID.SC-03 outcome not achieved | Medium | IDENTIFY Function Gap |
CWE Categories