Questions and comments about Cybersecurity Supply Chain Risk Management (C-SCRM) are always welcome and can be directed to [email protected]. When a public comment period for a C-SCRM publication is open, contact information for providing feedback on it will be listed in the "Status" column of the table below.
The following C-SCRM guidance documents are in progress:
| Title | Series & Number | Public Comment Period | Status |
|---|---|---|---|
| NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick Start Guide | Special Publication (SP) 1326 | CLOSED | Undergoing final editorial review |
| Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems | SP 800-18 Revision 2 | CLOSED |
Incorporating comments from the public comment period |
To contact the NIST C-SCRM team about speaking at your organization's event, please use our Speaker Request Form.
Security and Privacy: controls assessment, cybersecurity supply chain risk management, information sharing, malware, risk assessment, security controls, security measurement, security programs & operations, systems security engineering, vulnerability management
Technologies: cloud & virtualization, hardware, software & firmware
Applications: communications & wireless, cybersecurity framework
Laws and Regulations: Comprehensive National Cybersecurity Initiative, Cybersecurity Enhancement Act, Cybersecurity Strategy and Implementation Plan, Cyberspace Policy Review, Executive Order 13636, Federal Acquisition Regulation, Federal Information Security Modernization Act, Homeland Security Presidential Directive 12, OMB Circular A-130