A policy establishing requirements for assessing and managing cybersecurity risks from vendors and business partners.