Regarding supply chain management, if you want to deeply align with international standards and implement best practices, it may be useful to refer to the following standards:
NIST SP 800-161
NIST SP 800-161, "Supply Chain Risk Management Practices for Federal Information Systems and Organizations", April 2015.
ISO/IEC 27036
ISO/IEC 27036 - Information Security for Supplier Relationships (four parts): This standard focuses on managing security risks in supplier relationships, including risk assessment and security requirements for suppliers.
ISO 28002
- ISO 28002:2011 - "Security Management Systems for the Supply Chain" provides a framework for establishing, implementing, and improving supply chain security management systems, addressing risks related to people, technology, and processes.