# GV.SC-01 — A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

- **Subcategory ID:** GV.SC-01
- **CSF function:** [GV](/md/csf/GV.md) — Govern

## Mapped controls

- [PM-30](/md/controls/PM-30.md)
- [SR-2](/md/controls/SR-2.md)
- [SR-3](/md/controls/SR-3.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
