STA

Supply Chain Management, Transparency, and Accountability

Domain definition — mapping in progress (source: AI Controls Matrix (AICM) Introductory Guidance).

16

Control objectives

21

Skills

4

Cross-cutting

—

Objectives fitted

AISMM maturity context

Risk & Provider Assessment & Management · Procedural domain

L1 InitialL2 RepeatableL3 DefinedL4 CapableL5 Efficient

A lens, not a partition. How AISMM adoption works →

Control objectives

The exact things this domain must do. Each carries an authoritative crosswalk to 9 external control sets (Cloud Security Alliance (CSA) AI Controls Matrix (AICM) v1.1.0). Fitted skills are drawn from the pool below as fits are evidenced.

Supply Chain Risk Management Policies and ProceduresSTA-01

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 14 steps
Application Provider — 8 steps
Model Provider — 8 steps
Orchestrated Services Provider — 8 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

SSRM Policy and ProceduresSTA-02

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 8 steps
Application Provider — 9 steps
Model Provider — 8 steps
Orchestrated Services Provider — 10 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

SSRM Supply ChainSTA-03

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 6 steps
Application Provider — 3 steps
Model Provider — 4 steps
Orchestrated Services Provider — 4 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

SSRM GuidanceSTA-04

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 3 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

SSRM Control OwnershipSTA-05

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

SSRM Documentation ReviewSTA-06

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 4 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

SSRM Control ImplementationSTA-07

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 6 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Supply Chain InventorySTA-08

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 7 steps
Application Provider — 3 steps
Model Provider — 3 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Service Bill of Material (BOM)STA-09

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 11 steps
Application Provider — 6 steps
Model Provider — 6 steps
Orchestrated Services Provider — 6 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Supply Chain Risk ManagementSTA-10

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 6 steps
Application Provider — 3 steps
Model Provider — 3 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Primary Service and Contractual AgreementSTA-11

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 4 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Supply Chain Agreement ReviewSTA-12

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 4 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Supply Chain Compliance AssessmentSTA-13

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 6 steps
Application Provider — 3 steps
Model Provider — 3 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Supply Chain Service Agreement ComplianceSTA-14

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4CCM v4.0.13AICPA TSC 2017ISO/IEC 27001:2022ISO/IEC 27002:2022NIST 800-53 rev 5NIST CSF v2.0

Implementation & auditing guidance

Shared implementation — 6 steps
Cloud Service Provider — 6 steps
Application Provider — 3 steps
Model Provider — 3 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Supply Chain Governance ReviewSTA-15

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 7 steps
Cloud Service Provider — 5 steps
Application Provider — 2 steps
Model Provider — 2 steps
Orchestrated Services Provider — 2 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Supply Chain Data Security AssessmentSTA-16

Crosswalk

ISO/IEC 42001EU AI ActBSI AIC4

Implementation & auditing guidance

Shared implementation — 5 steps
Cloud Service Provider — 8 steps
Application Provider — 4 steps
Model Provider — 4 steps
Orchestrated Services Provider — 3 steps

Verbatim Cloud Security Alliance (CSA) implementation & auditing steps are available to the owner.

Fitted skill — mapping in progress. Candidates are drawn from this domain’s skill pool below.

Standard names and gap levels shown; the specific clause references and full control text are available to the owner.

Skill pool — STA

Analyzing SBOM For Supply Chain VulnerabilitiesDetecting Typosquatting Packages In Npm PypiImplementing Sigstore For Software SigningDetect MCP Plugin Supply ChainDrafting GDPR Article 28 Data Processing AgreementsCloud Provider Privacy Risk AssessmentSAAS Vendor Privacy InventorySub Processor Management GDPR Art28Vendor Breach Notification CascadeVendor Privacy Certification AcceptanceVendor Privacy Monitoring ProgramVendor Privacy Audit Program

Sample view. 12 of 21 skill names shown; the full list is available to the owner.