Skip to content
#

nist-800-161

Here are 2 public repositories matching this topic...

A complete third-party vendor security risk-assessment framework — questionnaire, live scoring engine, and worked vendor assessments with approve/conditions/reject recommendations. Two-axis inherent×control residual-risk model mapped to NIST 800-161, ISO 27001 & SOC 2.

  • Updated Aug 31, 2026
  • Python

Third-party and software supply chain risk assessment of the 2026 open-source compromise wave (Trivy, Bitwarden, Checkmarx → OpenAI/Vercel downstream). Full GRC workflow: methodology, risk register, NIST CSF 2.0 / ISO 27001 / SP 800-161 control mapping, TPRM program response, KRIs, and board briefing. OSFI B-10/B-13 context.

  • Updated Jul 18, 2026

Add this topic to your repo

To associate your repository with the nist-800-161 topic, visit your repo's landing page and select "manage topics."

Learn more