Logo

CISOBot - Your AI CISO Assistant

AST-17

Prohibited Equipment & Services

Weight: 9/10
Description

Mechanisms exist to govern Supply Chain Risk Management (SCRM) sanctions that require the removal and prohibition of certain Technology Assets, Applications and/or Services (TAAS) that are designated as supply chain threats by a statutory or regulatory body.

Control Question

Does the organization govern Supply Chain Risk Management (SCRM) sanctions that require the removal and prohibition of certain Technology Assets, Applications and/or Services (TAAS) that are designated as supply chain threats by a statutory or regulatory body?

Control Metadata
Domain:

Asset Management

Validation Cadence:

Semi-Annual

Evidence Request List:

E-AST-10

Have questions about this control?

Ask CISOBot for implementation guidance and best practices