April 16, 2018 Cybersecurity Framework Version 1.1 between multiple levels of organizations. Supply chains begin with the sourcing of products and services and extend from the design, development, manufacturing, processing, handling, and delivery of products and services to the end user. Given these complex and interconnected relationships, supply chain risk management (SCRM) is a critical organizational function.11 Cyber SCRM is the set of activities necessary to manage cybersecurity risk associated with external parties. More specifically, cyber SCRM addresses both the cybersecurity effect an organization has on external parties and the cybersecurity effect external parties have on an organization. A primary objective of cyber SCRM is to identify, assess, and mitigate “products and services that may contain potentially malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the cyber supply chain12.” Cyber SCRM activities may include:      Determining cybersecurity requirements for suppliers, Enacting cybersecurity requirements through formal agreement (e.g., contracts), Communicating to suppliers how those cybersecurity requirements will be verified and validated, Verifying that cybersecurity requirements are met through a variety of assessment methodologies, and Governing and managing the above activities. As depicted in Figure 3, cyber SCRM encompasses technology suppliers and buyers, as well as non-technology suppliers and buyers, where technology is minimally composed of information technology (IT), industrial control systems (ICS), cyber-physical systems (CPS), and connected devices more generally, including the Internet of Things (IoT). Figure 3 depicts an organization at a single point in time. However, through the normal course of business operations, most organizations will be both an upstream supplier and downstream buyer in relation to other organizations or end users. 11 Communicating Cybersecurity Requirements (Section 3.3) and Buying Decisions (Section 3.4) address only two uses of the Framework for cyber SCRM and are not intended to address cyber SCRM comprehensively. 12 NIST Special Publication 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations, Boyens et al, April 2015, https://doi.org/10.6028/NIST.SP.800-161 This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018 16

Select target paragraph3