Cybersecurity Supply Chain Risk Management | CSRC | CSRC (2024)

Latest updates:

Information, communications, and operational technology (ICT/OT) users rely on a complex, globally distributed, and interconnected supply chain ecosystem to provide highly refined, cost-effective, and reusable solutions. This ecosystem is composed of various entities with multiple tiers of outsourcing, diverse distribution routes, assorted technologies, laws, policies, procedures, and practices, all of which interact to design, manufacture, distribute, deploy, use, maintain, dispose of, and otherwise manage products and services. These aspects of the supply chain include IT, OT, Communications, Internet of Things (IoT), and Industrial IoT.

The NIST Cybersecurity Supply Chain Risk Management (C-SCRM) program helps organizations to manage the increasing risk of supply chain compromise related to cybersecurity, whether intentional or unintentional. The factors that allow for low-cost, interoperability, rapid innovation, a variety of product features, and other benefits also increase the risk of a compromise to the supply chain, which may result in risks to the end user. Managing cybersecurity risks in supply chains requires ensuring the integrity, security, quality and resilience of the supply chain and its products and services. Risks may include insertion of counterfeits, unauthorized production, tampering, theft, insertion of malicious software and hardware, as well as poor manufacturing and development practices in the cybersecurity-related elements of the supply chain.

C-SCRM involves identifying, assessing, and mitigating the risks associated with the distributed and interconnected nature of ICT/OT product and service supply chains. It covers the entire life cycle of a system (including design, development, distribution, deployment, acquisition, maintenance, and destruction). NIST conducts research, provides resources, and convenes stakeholders to assist organizations in managing these risks.

Two new NIST efforts relate to the May 12, 2021 Executive Order 14028, Improving the Nation’s Cybersecurity, and a National Initiative for Improving Cybersecurity in Supply Chains.

NIST Approach

NIST is responsible for developing reliable and practical standards, guidelines, tests, and metrics to help protect non-national security federal information and communications infrastructure. Private sector and other government organizations also rely heavily on these NIST-produced resources. That includes organizations developing or using information, communications, and operational technologies which depend upon complex, globally distributed and interconnected supply chains.

Since 2008, NIST has conducted research and collaborated with a large number and variety of stakeholders to produce information resources which help organizations with their C-SCRM.By statute, federal agencies must use NIST’s C-SCRM and other cybersecurity standards and guidelines to protect non-national security federal information and communications infrastructure.The SECURE Technology ActandFASC Rulegave NIST specific authority to develop C-SCRM guidelines. NIST also is a member of the Federal Acquisition Security Council (FASC).

NIST has given several grants to conduct research in this area as well as to develop a web-based risk assessment and collaboration tool.

Managing cybersecurity risk in supply chains requires ensuring the integrity, security, quality, and resilience of the supply chain and its products and services. NIST focuses on:

  • Foundational practices: C-SCRM lies at the intersection of information security and supply chain management. Existing supply chain and cybersecurity practices provide a foundation for building an effective risk management program.
  • Enterprise-wide practices: Effective C-SCRM is an enterprise-wide activity that involves each tier (Organization, Mission/Business Processes, and Information Systems) and is implemented throughout the system development life cycle.
  • Risk management processes: C-SCRM should be implemented as part of overall risk management activities. That involves identifying and assessing applicable risks and determining appropriate response actions, developing a C-SCRM Strategy and Implementation Plan to document selected response actions, and monitoring performance against that plan.
    • Risk: Cybersecurity-related supply chain risk is associated with a lack of visibility into, understanding of, and control over many of the processes and decisions involved in the development and delivery of cyber products and services.
    • Threats and Vulnerabilities: Effectively managing cybersecurity risks in supply chains requires a comprehensive view of threats and vulnerabilities. Threats can be either “adversarial” (e.g., tampering, counterfeits) or “non-adversarial” (e.g., poor quality, natural disasters). Vulnerabilities may be “internal” (e.g., organizational procedures) or “external” (e.g., part of an organization’s supply chain).
  • Critical systems: Cost-effective supply chain risk mitigation requires organizations to identify those systems/components that are most vulnerable and will cause the largest organizational impact if compromised.
Cybersecurity Supply Chain Risk Management | CSRC | CSRC (2024)
Top Articles
The importance of AP Exams - Carnegie Prep
Handling Internship Rejection Like a Pro - The Intern Hustle
Why Are Fuel Leaks A Problem Aceable
Fan Van Ari Alectra
Time in Baltimore, Maryland, United States now
Froedtert Billing Phone Number
Citibank Branch Locations In Orlando Florida
oklahoma city for sale "new tulsa" - craigslist
<i>1883</i>'s Isabel May Opens Up About the <i>Yellowstone</i> Prequel
Sprague Brook Park Camping Reservations
Nm Remote Access
Crazybowie_15 tit*
A Fashion Lover's Guide To Copenhagen
World of White Sturgeon Caviar: Origins, Taste & Culinary Uses
Savage X Fenty Wiki
Zürich Stadion Letzigrund detailed interactive seating plan with seat & row numbers | Sitzplan Saalplan with Sitzplatz & Reihen Nummerierung
Wildflower1967
VMware’s Partner Connect Program: an evolution of opportunities
N2O4 Lewis Structure & Characteristics (13 Complete Facts)
Bx11
St Maries Idaho Craigslist
Aldine Isd Pay Scale 23-24
Forum Phun Extra
St. Petersburg, FL - Bombay. Meet Malia a Pet for Adoption - AdoptaPet.com
Tripadvisor Napa Restaurants
Baja Boats For Sale On Craigslist
Academy Sports Meridian Ms
Inbanithi Age
Urban Dictionary Fov
Meet the Characters of Disney’s ‘Moana’
Mobile crane from the Netherlands, used mobile crane for sale from the Netherlands
Log in or sign up to view
Ice Dodo Unblocked 76
Best Laundry Mat Near Me
Funky Town Gore Cartel Video
Taktube Irani
Kristen Hanby Sister Name
A Grade Ahead Reviews the Book vs. The Movie: Cloudy with a Chance of Meatballs - A Grade Ahead Blog
Baddies Only .Tv
How to Draw a Bubble Letter M in 5 Easy Steps
Police Academy Butler Tech
THE 10 BEST Yoga Retreats in Konstanz for September 2024
Dallas City Council Agenda
Tiny Pains When Giving Blood Nyt Crossword
Htb Forums
Craigslist Odessa Midland Texas
Acts 16 Nkjv
Yale College Confidential 2027
FedEx Authorized ShipCenter - Edouard Pack And Ship at Cape Coral, FL - 2301 Del Prado Blvd Ste 690 33990
Maplestar Kemono
Advance Auto.parts Near Me
Latest Posts
Article information

Author: Gregorio Kreiger

Last Updated:

Views: 6090

Rating: 4.7 / 5 (57 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Gregorio Kreiger

Birthday: 1994-12-18

Address: 89212 Tracey Ramp, Sunside, MT 08453-0951

Phone: +9014805370218

Job: Customer Designer

Hobby: Mountain biking, Orienteering, Hiking, Sewing, Backpacking, Mushroom hunting, Backpacking

Introduction: My name is Gregorio Kreiger, I am a tender, brainy, enthusiastic, combative, agreeable, gentle, gentle person who loves writing and wants to share my knowledge and understanding with you.