SID-ORG-04 — Supplier and Third-Party Security
| Property | Value |
|---|
| Status | to_do |
| Owner | operator |
| Category | policy |
| CSF Function | govern |
| Group | Governance and Policy Controls |
Description
Assess and manage information security risks from suppliers, including
the SirosID platform provider (Siros Foundation). Maintain supplier
agreements addressing security requirements, audit rights, incident
notification, and SLAs. Monitor the ICT supply chain for compromised
components (dependencies, libraries).
Audit Findings
| Finding | Severity | Status |
|---|
| ISO-O-12 — Partial supply chain security | medium | open |