• Latest
  • Trending
  • All
NIST Shares Cyber Supply Chain Risk Management Guidance

NIST Shares Cyber Supply Chain Risk Management Guidance

February 8, 2020
Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

April 23, 2024
Top 5 Spend Analysis Software ranked in 2024

Top 5 Spend Analysis Software ranked in 2024

March 1, 2024
How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

January 19, 2024
LATAM Cargo strengthens European cargo links

LATAM Cargo strengthens European cargo links

April 14, 2020
Ford making reusable hospital gowns from airbag materials as efforts against coronavirus expand

Ford making reusable hospital gowns from airbag materials as efforts against coronavirus expand

April 14, 2020
Don’t Sweat NBC’s Decision to Cut Back on Television Ad Inventory

Don’t Sweat NBC’s Decision to Cut Back on Television Ad Inventory

April 14, 2020
Software firms sharpen focus on AI, big data as IT spending drops

Software firms sharpen focus on AI, big data as IT spending drops

April 14, 2020
Navigating turbulent times in your supply chain (TL:DR version)

Navigating turbulent times in your supply chain (TL:DR version)

April 14, 2020
Last Mile Delivery by Drones Market is Booming Worldwide

Last Mile Delivery by Drones Market is Booming Worldwide

April 14, 2020
AIR CARGO MARKET SIZE, SHARE, DEMAND, TREND, LATEST INNOVATIONS & APPLICATION ANALYSIS AND INDUSTRY GROWTH FORECAST 2027 – Science In Me

AIR CARGO MARKET SIZE, SHARE, DEMAND, TREND, LATEST INNOVATIONS & APPLICATION ANALYSIS AND INDUSTRY GROWTH FORECAST 2027 – Science In Me

April 14, 2020
Wheat procurement in Patiala: 6,500 coupons issued to farmers – cities

Wheat procurement in Patiala: 6,500 coupons issued to farmers – cities

April 14, 2020
Pandemic, Plastics And The Continuing Quest For Sustainability

Pandemic, Plastics And The Continuing Quest For Sustainability

April 14, 2020
  • Supply Chain
  • Logistics
  • Warehousing
  • Procurement
  • Shipping
  • More
    • Strategic Sourcing
    • Spend Analysis
    • Inventory
    • Contact Us
No Result
View All Result
United States International Supply Chain Commission
United States International Supply Chain Commission
Home Supply Chain

NIST Shares Cyber Supply Chain Risk Management Guidance

by usiscc
February 8, 2020
in Supply Chain
0
NIST Shares Cyber Supply Chain Risk Management Guidance
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

By Jessica Davis

February 05, 2020 – NIST unveiled its latest draft guidance around cyber supply chain management, designed to help organizations develop an effective risk management program. Industry stakeholders are being asked to provide feedback by March 4.

The proposed Key Practices in Cyber Supply Chain Risk Management: Observations from Industry is based on an analysis of interviews held between 2015 and 2019, which NIST then developed into 24 case studies. The draft guidance contains six new case studies.

The guide also contains prior NIST research into cyber supply chain risk management, as well as industry standards and best practice documents. It’s aimed at those subject matter experts tasked with leading their organization’s risk management program.

Dig Deeper

Supply chain risk is prominent in healthcare, given its reliance on a host of third-party vendors and other business associates. Adding to the heightened risk are various threat actors that target healthcare and tech organizations’ supply chain vendors, including the hacking group behind the ransomware known as Zeppelin.

In April 2019, Carbon Black reported that 50 percent of cyberattacks target supply chain seeking lateral movement across connected partners, while Microsoft researchers noted a steep increase in supply chain attacks in March 2019.

“In today’s highly connected world, all organizations rely on other organizations for critical products and services,” NIST researchers wrote. “However, today’s world of globalization, while providing many benefits, has resulted in a world where organizations no longer fully control—and often do not have full visibility into—the supply ecosystems of the products that they make or the services that they deliver.”

“Organizations can no longer protect themselves by simply securing their own infrastructures since their electronic perimeter is no longer meaningful,” they continued. “Threat actors intentionally target the suppliers of more cyber-mature organizations to take advantage of the weakest link.”

NIST is seeking comment on several areas with hopes stakeholders will provide input on the key practices and recommendations contained in the guide, as they are designed to apply to organizations of all sizes across all sectors.

The guide is meant to be used to develop a cyber supply chain risk management program, combining industry and government resources with the information gathered through NIST research.

Organizations should be able to leverage the guide to implement an effective, formalized program, while helping organizations know and manage critical suppliers and understand the supply chain function.

Further, the guidance can help leaders understand how to closely collaborate with key suppliers, while including them within enterprise resilience and improvement activities. There are also best practice insights into assessing and monitoring the supplier relationship and planning for the full lifecycle.

“Each key practice includes a number of recommendations, which synthesize how these practices can be implemented from a people, process, and technology perspective,” researchers wrote. “These and several other recommendations are mapped to each of the key practices to help the readers implement effective C-SCRM practices in their organizations.”

Those recommendations center around creating explicit collaborative roles, structures, and process for supply chain, cybersecurity, product security, and physical security (and other relevant) functions, integrating cybersecurity considerations into the system and product lifecycle, determining supplier criticality with standards and best practices, and other crucial supplier relationship insights.

Industry stakeholders can provide feedback until March 4. The supply chain guidance joins other NIST guides currently in progress, including the latest insights around ransomware and other data integrity attacks.

Healthcare providers should look to the proposed guidance for insights into supply chain management, as well as healthcare-specific guidance on the topic released by the Healthcare and Public Health Sector Coordinating Council in October.


Share197Tweet123
usiscc

usiscc

  • Trending
  • Comments
  • Latest
Escape From Tarkov – How to Rotate Items

Escape From Tarkov – How to Rotate Items

February 5, 2020
Supply chain examination: Planning for vulnerabilities you can’t control

Supply chain examination: Planning for vulnerabilities you can’t control

December 7, 2019
Procurement Project Manager job with Camden London Borough Council

Procurement Project Manager job with Camden London Borough Council

February 17, 2020
Art Battle Wichita Falls III at The Warehouse, 1401 Lamar.

Art Battle Wichita Falls III at The Warehouse, 1401 Lamar.

0
Global Industry Analysis, Size, Share, Growth, Trends, and Forecasts 2016–2024 – ZMR News Reports

Global Industry Analysis, Size, Share, Growth, Trends, and Forecasts 2016–2024 – ZMR News Reports

0
PHOTOS: Ottawa firefighters respond to warehouse fire

PHOTOS: Ottawa firefighters respond to warehouse fire

0
Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

April 23, 2024
Top 5 Spend Analysis Software ranked in 2024

Top 5 Spend Analysis Software ranked in 2024

March 1, 2024
How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

January 19, 2024
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • DMCA
  • Contact Us

Copyright © 2024 United States International Supply Chain Commission (usiscc.org)

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT
No Result
View All Result
  • Supply Chain
  • Logistics
  • Warehousing
  • Procurement
  • Shipping
  • More
    • Strategic Sourcing
    • Spend Analysis
    • Inventory
    • Contact Us

Copyright © 2024 United States International Supply Chain Commission (usiscc.org)