{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Framework: The NIST Cybersecurity Framework (CSF)","title":"GV.SC-01 - Building a Supply Chain Risk Management Program","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/3559899c\"></iframe>","width":"100%","height":180,"duration":1220,"description":"GV.SC-01 focuses on creating a structured cybersecurity supply chain risk management program that includes a clear strategy, objectives, policies, and processes, all endorsed by organizational stakeholders. This ensures that risks stemming from suppliers and third-party relationships are systematically addressed, with a defined plan that outlines milestones and responsibilities. Stakeholder agreement reinforces the program’s legitimacy and aligns it with broader organizational goals.\nThis subcategory establishes a foundation for managing supply chain risks by integrating cybersecurity considerations into procurement and vendor interactions. It promotes collaboration across functions like IT, legal, and operations to ensure the program is actionable and effective. GV.SC-01 sets the stage for a proactive, organization-wide approach to securing the supply chain.","thumbnail_url":"https://img.transistorcdn.com/ZQAUShkq6bmReWtsoCApAiEqnASSjulPAjN3RZCtsFI/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YTE2/ZTU4ZDc5YjBhMjRj/MDkxMTllN2RmZDU5/YmU2My5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}