April 16, 2018
Cybersecurity Framework
Version 1.1
between multiple levels of organizations. Supply chains begin with the sourcing of products and
services and extend from the design, development, manufacturing, processing, handling, and
delivery of products and services to the end user. Given these complex and interconnected
relationships, supply chain risk management (SCRM) is a critical organizational function.11
Cyber SCRM is the set of activities necessary to manage cybersecurity risk associated with
external parties. More specifically, cyber SCRM addresses both the cybersecurity effect an
organization has on external parties and the cybersecurity effect external parties have on an
organization.
A primary objective of cyber SCRM is to identify, assess, and mitigate “products and services
that may contain potentially malicious functionality, are counterfeit, or are vulnerable due to
poor manufacturing and development practices within the cyber supply chain12.” Cyber SCRM
activities may include:
Determining cybersecurity requirements for suppliers,
Enacting cybersecurity requirements through formal agreement (e.g., contracts),
Communicating to suppliers how those cybersecurity requirements will be verified
and validated,
Verifying that cybersecurity requirements are met through a variety of assessment
methodologies, and
Governing and managing the above activities.
As depicted in Figure 3, cyber SCRM encompasses technology suppliers and buyers, as well as
non-technology suppliers and buyers, where technology is minimally composed of information
technology (IT), industrial control systems (ICS), cyber-physical systems (CPS), and connected
devices more generally, including the Internet of Things (IoT). Figure 3 depicts an organization
at a single point in time. However, through the normal course of business operations, most
organizations will be both an upstream supplier and downstream buyer in relation to other
organizations or end users.
11
Communicating Cybersecurity Requirements (Section 3.3) and Buying Decisions (Section 3.4) address only two
uses of the Framework for cyber SCRM and are not intended to address cyber SCRM comprehensively.
12
NIST Special Publication 800-161, Supply Chain Risk Management Practices for Federal Information Systems
and Organizations, Boyens et al, April 2015, https://doi.org/10.6028/NIST.SP.800-161
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
16