ABSTRACT

Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations   [open pdf - 4MB]

From the Abstract: "Organizations are concerned about the risks associated with products and services that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the supply chain. These risks are associated with an enterprise's decreased visibility into and understanding of how the technology they acquire is developed, integrated, and deployed or the processes, procedures, standards, and practices used to ensure the security, resilience, reliability, safety, integrity, and quality of the products and services. This publication provides guidance to organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations. The publication integrates cybersecurity supply chain risk management (C-SCRM) into risk management activities by applying a multilevel, C-SCRM-specific approach, including guidance on the development of C-SCRM strategy implementation plans, C-SCRM policies, C-SCRM plans, and risk assessments for products and services."

Report Number:
National Institute of Standards and Technology Special Publication 800-161r1
Author:
Publisher:
Date:
2022-05
Copyright:
Public Domain
Retrieved From:
National Institute of Standards and Technology (NIST): https://www.nist.gov/
Format:
pdf
Media Type:
application/pdf
URL:
Help with citations