GV.SC-10.117
Does your organization have a documented process for terminating or transitioning supplier relationships that specifically addresses supply chain security risks and resilience?
Explanation
This question assesses whether your organization has formal procedures to manage the security implications when ending or changing supplier relationships. Without proper termination/transition planning, organizations risk data breaches, service disruptions, or compliance violations during these critical periods. Evidence could include a formal supplier offboarding policy document, transition plan templates that include security considerations, or completed supplier transition plans that demonstrate how security risks were addressed during previous supplier changes.
Implementation Example
Develop and execute a plan for terminating or transitioning supplier relationships that takes supply chain security risk and resiliency into account
ID: GV.SC-10.117
Context
- Function
- GV: GOVERN
- Category
- GV.SC: Cybersecurity Supply Chain Risk Management
- Sub-Category
- Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

