Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-161 Rev. 1

Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

Date Published: May 2022

Supersedes: SP 800-161 (04/08/2015)

Author(s)

Jon Boyens (NIST), Angela Smith (NIST), Nadya Bartol (Boston Consulting Group), Kris Winkler (Boston Consulting Group), Alex Holbrook (Boston Consulting Group), Matthew Fallon (Boston Consulting Group)

Abstract

Keywords

acquire; C-SCRM; cybersecurity supply chain; cybersecurity supply chain risk management; information and communication technology; risk management; supplier; supply chain; supply chain risk assessment; supply chain assurance; supply chain risk; supply chain security
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.800-161r1
Download URL

Supplemental Material:
NIST’s Cyber Supply Chain Risk Management Program
NIST news article (May 2022)

Related NIST Publications:
Other

Document History:
02/04/20: SP 800-161 Rev. 1 (Draft)
04/29/21: SP 800-161 Rev. 1 (Draft)
10/28/21: SP 800-161 Rev. 1 (Draft)
05/05/22: SP 800-161 Rev. 1 (Final)

Topics

Security and Privacy

acquisition, cybersecurity supply chain risk management

Laws and Regulations

Executive Order 14028