Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

A  |  B  |  C  |  D  |  E  |  F  |  G  |  H  |  I  |  J  |  K  |  L  |  M  |  N  |  O  |  P  |  Q  |  R  |  S  |  T  |  U  |  V  |  W  |  X  |  Y  |  Z

Cybersecurity Supply Chain Risk Management

Definitions:

  The process of identifying, assessing, and mitigating the risks associated with the global and distributed nature of information and communications technology product and service supply chains.
Sources:
NIST SP 800-18r2 under supply chain risk management from OMB Circular A-130 (2016)
NIST SP 800-37 Rev. 2 under supply chain risk management from OMB Circular A-130 (2016)

  A systematic process for managing cyber supply chain risk exposures, threats, and vulnerabilities throughout the supply chain and developing risk response strategies to the risks presented by the supplier, the supplied products and services, or the supply chain.
Sources:
NIST SP 800-53 Rev. 5 under supply chain risk management
NIST SP 800-53A Rev. 5 under supply chain risk management

  A systematic process for managing exposure to cybersecurity risks throughout the supply chain and developing appropriate response strategies, policies, processes, and procedures.
Sources:
NIST SP 800-18r2 under cybersecurity supply chain risk management from NIST SP 800-161r1-upd1