April 16, 2018
Cybersecurity Framework
Version 1.1
Figure 3: Cyber Supply Chain Relationships
The parties described in Figure 3 comprise an organization’s cybersecurity ecosystem. These
relationships highlight the crucial role of cyber SCRM in addressing cybersecurity risk in critical
infrastructure and the broader digital economy. These relationships, the products and services
they provide, and the risks they present should be identified and factored into the protective and
detective capabilities of organizations, as well as their response and recovery protocols.
In the figure above, “Buyer” refers to the downstream people or organizations that consume a
given product or service from an organization, including both for-profit and not-for-profit
organizations. “Supplier” encompasses upstream product and service providers that are used for
an organization’s internal purposes (e.g., IT infrastructure) or integrated into the products or
services provided to the Buyer. These terms are applicable for both technology-based and nontechnology-based products and services.
Whether considering individual Subcategories of the Core or the comprehensive considerations
of a Profile, the Framework offers organizations and their partners a method to help ensure the
new product or service meets critical security outcomes. By first selecting outcomes that are
relevant to the context (e.g., transmission of Personally Identifiable Information (PII), mission
critical service delivery, data verification services, product or service integrity) the organization
then can evaluate partners against those criteria. For example, if a system is being purchased that
will monitor Operational Technology (OT) for anomalous network communication, availability
may be a particularly important cybersecurity objective to achieve and should drive a
Technology Supplier evaluation against applicable Subcategories (e.g., ID.BE-4, ID.SC-3,
ID.SC-4, ID.SC-5, PR.DS-4, PR.DS-6, PR.DS-7, PR.DS-8, PR.IP-1, DE.AE-5).
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
17