The Supply Chain Governance page is where you establish and oversee your organization's comprehensive supply chain risk management program, strategy, and objectives.
Go to app.maplegrc.com.
Log in with your account credentials.
From the homepage, navigate to the Supply Chain Governance Page section.
A built-in analysis tool for evaluating supply chain data and metrics.
The Objectives of Supply Chain Risk Management section is designed to define and track the strategic security goals for your vendor network. Based on the provided data snippet, this table organizes your high-level targets to ensure they meet your organization's supply chain governance standards.
Here is a breakdown of what each column represents:
BSC Perspective: The business angle. This indicates which general area of the company this goal supports (such as Financial, Customer, or Internal Processes).
Cybersecurity Objective: The security target. The specific protection goal you want to achieve with your vendors (like preventing data leaks).
Supply Chain Management Objective: The operational target. The overarching business goal for your vendor network (like ensuring continuous, uninterrupted service).
Shared Responsibility in Cloud: The division of duties. This clarifies exactly who is on the hook for protecting specific parts of the technology—your organization or the cloud vendor.
Measure: The tracking method. The general tool, process, or approach you will use to measure success.
GQM Goal: The big picture. What you are ultimately trying to achieve (the "Goal" in the Goal-Question-Metric framework).
GQM Question: The test. The specific question you must ask to determine if you are actually meeting that goal.
GQM KPI: The actual number. The specific metric or data point (Key Performance Indicator) you track to answer the question.
Risk Tolerance: The safety buffer. The exact amount of risk, error, or failure your organization is willing to accept before it requires an immediate response.
The Vendors Metrics section is designed to track and evaluate key performance, resilience, and compliance indicators for your third-party service providers. Based on the provided data snippet, this table organizes critical vendor parameters to ensure they meet your organization's supply chain governance standards.
Here is a breakdown of what each column represents:
Vendor: The company or software you are using (e.g., Google Workspace, TSplus).
Model: How the software is delivered. "SaaS" just means it is a web-based app you log into, and "PaaS" means they provide a digital platform for your own team to build on.
SLA (Service Level Agreement): The uptime promise. This is where the vendor guarantees the software will be online and working a certain percentage of the time (like 99.9%).
RPO (Recovery Point Objective): The backup rule. If the system crashes, how much recent data are you okay with losing? (e.g., losing only the last hour of work).
RTO (Recovery Time Objective): The fix-it rule. If the system goes down, how fast do they have to get it running again?
Required Certification Scope: The specific security badges or compliance rules the vendor must hold to do business with you.
This section manages the ongoing audit requirements necessary to ensure continuous compliance across the supply chain. It specifically categorizes metrics by framework, including distinct sections for "Cloud Security Alliance Continuous Audit Metrics" and "MEDIA Continuous Audit Metrics". The catalogue tracks individual metrics using the following columns:
Metric ID
Metric Catalog
Metric Description
Metric Specification
Governance
Agreements / Reports (e.g., specific requirements such as "Maintain Performance Monitoring Documentation")