GAO: Agencies must ramp up supply chain risk management practices
acquisition
(Getty Images)
Dec 16, 2020 | FEDSCOOP
The report compares whether or not 23 civilian Chief Financial Officers Act agencies have implemented seven foundational practices for risk management — policies from developing an agencywide information and communications SCRM policy to creating SCRM standards for potential suppliers.
Six agencies have established a process to conduct an SCRM review of a potential supplier, the highest adoption rate of any of the seven practices. On the flip side, none of the agencies has established a process to conduct an agency-wide assessment of their information and communications technology supply chain risks, and 14 agencies hadn’t established any of the suggested practices.