
ID.SC-2: Supply Chain Risk Management
Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders.

ID.SC-1: Supply Chain Risk Management
Cybersecurity risks to organizational assets are identified and managed.

ID.RM-3: Risk Management Strategy
The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector-specific risk analysis.

ID.RM-2: Risk Management Strategy
Organizational risk tolerance is determined and clearly expressed.

ID.RM-1: Risk Management Strategy
Risk management processes are established, managed, and agreed to by organizational stakeholders.