PM-30 Supply Chain Risk Management Strategy

Program Management

New in Rev 5

Description

a. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services; b. Implement the supply chain risk management strategy consistently across the organization; and c. Review and update the supply chain risk management strategy on [Assignment: organization-defined frequency] or as required, to address organizational changes.

Supplemental Guidance

An organization-wide supply chain risk management strategy includes an unambiguous expression of the supply chain risk appetite and tolerance for the organization, acceptable supply chain risk mitigation strategies or controls, a process for consistently evaluating and monitoring supply chain risk, and approaches for implementing and communicating the supply chain risk management strategy.

Changes from Rev 4

New control in Rev 5. Formalizes supply chain risk management strategy.

Compliance Mappings

NIST CSF 2.0

GV.SC-01GV.SC-03GV.SC-09

PRA Operational Resilience

SS2/21-16.1

RBI CSF

Annex1.11ITGRCA.10

EU CRA

CRA.I.1

SAMA CSF

1.84.1

Qatar NIA

GV

CBUAE

CR-12

CBE CSF

CTO-11OVM-1

SA JS2

JS2-8.7

CBN CSF

Part2.4

BoG CISD

CISD-XVI

BoM CTRM

1.53.9

BCBS 239

Principle 1

FFIEC IS

II.C.20

NYDFS 500

500.11

SEBI CSCRF

GV.RMGV.SC

BOT Cyber Resilience

Ch5.1Ch5.2

DOE C2M2 v2.1

THIRD

ISAE 3402

Clause 7

Lloyd's Minimum Standards

MS10.1

NAIC Insurance Data Security

4D

FCA SYSC 13

SYSC 13.9.1