Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Cross-Framework Defense Map

GV.SC-09 — Life-Cycle Supply Chain Security

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

GV — Govern · GV.SC — Cybersecurity Supply Chain Risk Management

Open the full CSF learning profile →
Official NIST CSF outcome

GV.SC-09

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

Function: GovernCategory: Cybersecurity Supply Chain Risk Management
NIST informative reference

Related NIST SP 800-53 controls

The imported relationship is superset-of with source confidence 100%. This is navigation evidence, not a claim that implementing the listed controls automatically achieves the outcome.

CUI protection layer

NIST SP 800-171 and SP 800-172

These requirements cite the mapped SP 800-53 controls or enhancements. Applicability still depends on the governing contract, agency selection, and system context.

SP 800-171 Rev. 3 requirements

SP 800-172 Rev. 3 enhanced requirements

Defensive engineering layer

MITRE D3FEND techniques

Semantic relationship labels and the exact SP 800-53 source reference are preserved from the imported D3FEND mapping.

Show 2 additional relationships
Adversary layer

MITRE ATT&CK relationships

Curated ATT&CK mitigation mappings

Inferred ATT&CK behavior relationships

Experimental: These links are inferred through shared D3FEND artifacts and relationships. They are not guarantees that a technique prevents or detects an ATT&CK behavior.

Show 466 additional relationships
Bare Metal Cyber interpretation

Use the chain to ask better implementation questions.

  • Which mapped controls are actually selected and implemented for this system?
  • Which CUI requirements or enhanced requirements apply under the governing agreement?
  • Which D3FEND techniques are implemented as real technical capabilities, and what evidence proves they operate?
  • Which ATT&CK relationships are curated, and which are only inferred starting points for engineering analysis?
  • What book, podcast, or Academy lesson gives the team enough depth to make a defensible decision?
Sources and limitations

Relationship provenance

NIST OLIR informative-reference record ↗ · NIST CSF 2.0 ↗

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.