Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

Cross-Framework Defense Map

GV.SC-05 — Supply Chain Requirements in Agreements

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

GV — Govern · GV.SC — Cybersecurity Supply Chain Risk Management

Open the full CSF learning profile →
Official NIST CSF outcome

GV.SC-05

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

Function: GovernCategory: Cybersecurity Supply Chain Risk Management
NIST informative reference

Related NIST SP 800-53 controls

The imported relationship is superset-of with source confidence 100%. This is navigation evidence, not a claim that implementing the listed controls automatically achieves the outcome.

CUI protection layer

NIST SP 800-171 and SP 800-172

These requirements cite the mapped SP 800-53 controls or enhancements. Applicability still depends on the governing contract, agency selection, and system context.

SP 800-171 Rev. 3 requirements

SP 800-172 Rev. 3 enhanced requirements

Defensive engineering layer

MITRE D3FEND techniques

Semantic relationship labels and the exact SP 800-53 source reference are preserved from the imported D3FEND mapping.

No relationship is present in the currently imported source datasets.
Adversary layer

MITRE ATT&CK relationships

Curated ATT&CK mitigation mappings

No relationship is present in the currently imported source datasets.

Inferred ATT&CK behavior relationships

Experimental: These links are inferred through shared D3FEND artifacts and relationships. They are not guarantees that a technique prevents or detects an ATT&CK behavior.

No relationship is present in the currently imported source datasets.
Bare Metal Cyber interpretation

Use the chain to ask better implementation questions.

  • Which mapped controls are actually selected and implemented for this system?
  • Which CUI requirements or enhanced requirements apply under the governing agreement?
  • Which D3FEND techniques are implemented as real technical capabilities, and what evidence proves they operate?
  • Which ATT&CK relationships are curated, and which are only inferred starting points for engineering analysis?
  • What book, podcast, or Academy lesson gives the team enough depth to make a defensible decision?
Sources and limitations

Relationship provenance

NIST OLIR informative-reference record ↗ · NIST CSF 2.0 ↗

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.