← NIST CSF 2.0 · GOVERN — Supply Chain Risk Management

GV.SC-08 — Suppliers are included in incident planning and response

medium vendor-managementincident-response

Requirement

Relevant suppliers and other third parties are included in incident planning, response and recovery activities.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
suppliervendorthird party
Required element 2 — any one of
incidentresponsenotificationescalationnotifyescalat…
Supporting terms — specificity signals
contactslacontractual notificationjoint exercisetabletop

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.26 Joint controllers vendor-management
GDPR Art.28 Processors and processing agreements vendor-management
GDPR Art.33 Notification of a breach to the supervisory authority incident-response
GDPR Art.44-49 Transfers of personal data to third countries vendor-management
CCPA/CPRA 1798.100(d) Contracts with service providers, contractors and third parties vendor-management
SOC 2 CC2.3 External communication vendor-management
SOC 2 CC7.3 Evaluation of security events incident-response
SOC 2 CC7.4 Incident response programme incident-response