The organization shall conduct cyber supply chain risk assessments at least annually or when a change to the organization’s critical systems, operational environment, or supply chain occurs; These assessments shall be documented, and the results disseminated to relevant stakeholders including those responsible for ICT/OT systems.
A documented list of all the organization’s suppliers, vendors and partners who may be involved in a major incident shall be established, kept up-to-date and made available online and offline.