Annex 5.1.4
Mapped SPARTA techniques (4)
Techniques referencing this article
Direct-supplier security requirements (segmentation, monitoring discipline, vulnerability handling, incident-disclosure obligations) are the contractual mechanism that constrains how partner environments are operated; weak partner posture is the precondition for partner-site exfiltration.
Direct-supplier security requirements (vulnerability assessment, secure-development practices, disclosure obligations) are the procedural lever the entity uses to constrain which suppliers it accepts and to push security expectations down through the chain that supply-chain compromise traverses.
Direct-supplier security requirements (secure-handling practices, anti-counterfeit screening, tamper-evident packaging) are the contractual mechanism that constrains how hardware moves from foundry to final integration.
Supplier-quality requirements (vulnerability assessment, secure-development practices, disclosure obligations) are codified in the entity's supplier selection and contracting; weak third-party hygiene is what makes 3rd-party GS compromise viable.