Supply Chain Risk Management
What is Supply Chain Risk Management?
The process of identifying, assessing, and mitigating risks arising from the extended network of suppliers, vendors, and service providers. Supply chain risk management is addressed by NIST CSF 2.0, ISO 27001 A.5.21, and NIST SP 800-161.
Terms that appear alongside supply chain risk management
Each of these is named in at least one of the same controls as supply chain risk management. The number is how many controls name both.
- nist 12 shared controls
- cybersecurity 9 shared controls
- risk management plan 9 shared controls
- policy 8 shared controls
- integrity 6 shared controls
- audit 6 shared controls
- risk assessment 6 shared controls
- software bill of materials 5 shared controls
Frameworks that govern supply chain risk management
What the standards actually require on supply chain risk management
Requirements naming supply chain risk management across 6 standards, quoted from the control text.
Requires a supply chain risk management policy with supporting procedures to be developed, approved, disseminated to defined personnel, owned by a named official, and reviewed and updated on a defined frequency and after defined events.
NIST800-SR-1 · Policy and procedures for supply chain risk management →Dedicated supply chain risk management controls including the C-SCRM plan, supplier assessments, and component tamper resistance.
SP800-161-CONTROLS-SR · ICT SCRM Control Family: Supply Chain Risk Management →Develop a C-SCRM plan for managing supply chain risks for systems, components, and services; review and update at defined frequency.
SR-2 · Supply Chain Risk Management Plan (SR-2) →Develop a C-SCRM plan for managing supply chain risks for systems, components, and services; review and update at defined frequency.
SR-2 · Supply Chain Risk Management Plan (SR-2) →Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-03 · Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes →Requires a plan for managing supply chain risk for the system, reviewed and updated and protected from disclosure.
161R1-SR-2 · Supply Chain Risk Management Plan →Questions people ask about supply chain risk management
What is Supply Chain Risk Management?
Why is Supply Chain Risk Management important for compliance?
Which compliance frameworks address Supply Chain Risk Management?
Where can I learn more about Supply Chain Risk Management?
See how Supply Chain Risk Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.