An incident where an adversary exploits vulnerabilities in the product or service supply network of the intended target. Note 1: Supply chain attacks may be conducted at any point in a system lifecycle to exfiltrate or manipulate data, disrupt or manipulate system operations, or provide an adversary the ability to access, disrupt, or manipulate a system in the future. Note 2: The supply network of a product or service may be internal to a targeted organization (e.g. logistics services), or external (e.g. third-party product/service providers).
Sources:
CNSSI 4009-2022