Tech News, Magazine & Review WordPress Theme 2017
  • Supply Chain Updates
  • GLOBAL NEWS
  • REGIONAL NEWS
  • Industry Buzz
  • CURRENT ISSUES
No Result
View All Result
  • Supply Chain Updates
  • GLOBAL NEWS
  • REGIONAL NEWS
  • Industry Buzz
  • CURRENT ISSUES
No Result
View All Result
United States Supply Chain Management Council
No Result
View All Result
Home Supply Chain Updates

NIST releases draft guidebook for addressing supply chain cybersecurity

usscmc by usscmc
February 11, 2020
NIST releases draft guidebook for addressing supply chain cybersecurity
Share on FacebookShare on Twitter

Cyber security for supply chains

Technology products are commonly built using components and services supplied by third-party manufacturers and suppliers, making them difficult to secure effectively against malware and other threats. NIST

With a goal to reduce the cybersecurity risk to one of the most vulnerable aspects of commerce—global supply chains—the National Institute of Standards and Technology (NIST) has published a draft guidebook for businesses that presents a set of effective risk management techniques distilled by NIST’s computer security experts.

“Key Practices in Cyber Supply Chain Risk Management” provides a set of strategies to help businesses address the cybersecurity issues posed by modern information and communications technology products, which are commonly built using components and services supplied by third-party organizations. The composed nature of these devices and systems makes them difficult to secure effectively against malware and other threats, placing manufacturers, service providers, and end users at risk.

“The seed of the problem is that everything is interconnected nowadays,” said NIST’s Jon Boyens, one of the draft report’s authors. “Products are very sophisticated, and with our globalized economy, companies often outsource the tasks of developing components and code to other companies, involving multiple tiers of suppliers.”

Vulnerabilities in the cyber supply chain involve not only microchips and their internal code, but also the support software for a device and the other companies that have access to its components. Put them all together, and it can be a daunting task to anticipate every systemic weakness that an adversary might exploit.

The NIST report is a high-level document intended to be easily understood and applied in managing these risks. Its core is a 27-page section outlining eight key practices that have proved to be useful, from establishing a formal risk management program to collaborating closely with key suppliers. Each key practice is accompanied by a set of recommendations, and because each organization will have its own specific needs, the authors also include guidance on how to apply these recommendations.

Acknowledging that companies in different economic sectors might manage supply chain risk differently, the authors also offer a set of 24 case studies in risk management that feature a variety of businesses from aerospace and IT manufacturers to consumer goods companies.

Following public comments, NIST will release a final version in spring 2020.

usscmc

usscmc

No Result
View All Result

Recent Posts

  • Supply Chain Issues Delay Michigan Statehouse Welcome Center
  • Last Mile Delivery Market Size, Growth And Forecast
  • High shipping rates could increase inflation by 1.5%: IMF
  • Coast Guard responds to adrift cargo ship off California
  • Underinsurance as a Persistent Driver of Cross-Border Antibiotic Procurement in U.S. Border Communities

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
United States Supply Chain Management Council

Categories

  • Global News
  • Supply Chain Updates

Tags

APICS Globally Recognized Supply Chain Certifications IIPMR Certifications International Institute for Procurement and Market Research (IIPMR) ISM Next Level Purchasing Top 5 Supply Chain Certifications top supply chain certifications

Trending

No Content Available
  • Privacy Policy
  • Terms of Use
  • Antispam
  • Disclaimer
  • Contact Us

© 2022 www.usscmc.com

No Result
View All Result
  • Supply Chain Updates
  • GLOBAL NEWS
  • REGIONAL NEWS
  • Industry Buzz
  • CURRENT ISSUES

© 2022 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT