NIST 800-172_3.11.7e

NIST 800-172

3.11 RISK ASSESSMENT

3.11.7e

Develop a plan for managing supply chain risks associated with organizational systems and system components; update the plan [Assignment: organization-defined frequency].

Organizations need to implement a planned approach to counter supply chain risks. The growing dependence on products systems and services from external providers along with the nature of the relationships with those providers present an increasing level of risk to an organization. Threat actions that may increase risk include the insertion or use of counterfeits unauthorized production tampering theft insertion of malicious software and hardware and poor manufacturing and development practices in the supply chain. Supply chain risks can be endemic or systemic within a system element or component a system an organization a sector or the Nation. Managing supply chain risk is a multifaceted undertaking that requires a coordinated effort across an organization to build trust relationships and communicate with both internal and external stakeholders. Supply chain risk management (SCRM) activities involve identifying and assessing risks determining appropriate mitigating actions developing SCRM plans to document selected mitigating actions and monitoring performance against plans. SCRM plans address requirements for developing trustworthy secure and resilient systems and system components including the application of the security design principles implemented as part of life cycle-based systems security engineering processes. [SP 800-161] provides guidance on supply chain risk management

 

Click here to Start your FREE trial today!

Explainer video

 

What is a Cybersecurity Compliance Framework?

You don’t need to clutter your security and privacy programs with an ever-increasing number of tools as they become more sophisticated. The Lionfish platform offers a one-stop solution to track progress and monitor any framework, from custom-built ones to highly-specialized and in-demand top security and privacy frameworks and certifications.

With the Lionfish platform, every framework is supported with guided scoping, policies, controls, automated evidence collection, and continuous monitoring, ensuring efficient preparation for audits or attestation in minimal time.

The Lionfish platform is compatible with a wide range of security and privacy frameworks, including:

Click here to Start your FREE trial today!

Explainer video