{
  "node_id": "supply-chain-risk-triage",
  "title": "Supply Chain Risk Triage Protocol",
  "domain": "Logistics & Supply Chain",
  "version": "1.1.1",
  "last_updated": "2026-04-30",
  "bluf": "The Supply Chain Risk Triage Protocol mandates an immediate escalation and review process upon detection of specific high-risk conditions within the procurement and component lifecycle. This automated governance mechanism is triggered by a confluence of factors indicating severe potential disruption or compromise. An alert is generated if a supplier's security posture degrades significantly, evidenced by a security score delta of -15 or more points, or upon formal confirmation of a data breach (`supplier_breach_confirmed`). Physical integrity alerts, such as any positive indication of `tampering_evidence_detected`, also require instant intervention. From a cybersecurity perspective, the protocol activates when a component accumulates 3 or more critical Common Vulnerabilities and Exposures (`component_cve_count_critical`), especially when there is `threat_intel_correlation` suggesting active exploitation. The business continuity risk is a primary driver; an `estimated_business_impact_score` reaching 4 or higher necessitates a formal assessment. This is particularly acute for any `is_critical_supplier` or providers of a `is_sole_source_component`, especially when inventory levels drop below a critical threshold of 7 `inventory_days_of_supply`. Geopolitical factors are also evaluated, with suppliers located in a `is_high_risk_geo` automatically flagged. The absence of a pre-vetted alternative (`has_vetted_alternate`) for a compromised supply line compounds the risk severity and accelerates the required response timeline, ensuring that vulnerabilities are addressed with requisite urgency and according to established corporate policy and regulatory standards.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-28000-supply-chain",
    "wco-safe-framework",
    "c-tpat-minimum-security",
    "customs-tapa-transport-sec",
    "nist-ir-7622-scrm-practices",
    "iso-31000-risk-mgt-std"
  ],
  "primary_citations_count": 6
}