Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8276 (Initial Public Draft)

Key Practices in Cyber Supply Chain Risk Management: Observations from Industry

Date Published: February 2020
Comments Due: March 4, 2020 (public comment period is CLOSED)
Email Questions to: scrm-nist@nist.gov

Author(s)

Jon Boyens (NIST), Celia Paulsen (NIST), Nadya Bartol (Boston Consulting Group), Kris Winkler (Boston Consulting Group), James Gimbi (Boston Consulting Group)

Announcement

Since the release of the Framework for Improving Critical Infrastructure Cybersecurity (NIST Cybersecurity Framework) and its companion, Roadmap for Improving Critical Infrastructure Cybersecurity in 2014, NIST has researched industry practices in cyber supply chain risk management (C-SCRM) through engagement with industry leaders.

This publication is based on: an analysis of interviews with companies in 2015 and 2019, which led to the development of 24 case studies; prior NIST research in cyber supply chain risk management; and a number of standards and industry best practices documents. NISTIR 8276 is intended to provide a high-level summary of practices deemed by subject matter experts to be foundational to an effective cyber supply chain risk management program.

NOTE: A call for patent claims is included on page iv of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

For additional information, see the NIST news article, NIST Offers Strategies to Help Businesses Secure Their Cyber Supply Chains.

Abstract

Keywords

best practices; cyber supply chain risk management; C-SCRM; external dependency management; information and communication technology supply chain risk management; ICT SCRM; key practices; risk management; supplier; supply chain; supply chain assurance; supply chain risk; supply chain risk assessment; supply chain risk management; supply chain security; third-party risk management
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.IR.8276-draft
Download URL

Supplemental Material:
Cyber SCRM Key Practices and Case Studies
NIST news article

Document History:
02/04/20: IR 8276 (Draft)
02/11/21: IR 8276 (Final)

Topics

Security and Privacy

cybersecurity supply chain risk management

Applications

cybersecurity framework