NIST Invites Comments on Major Revision to Cyber Supply Chai

NIST Invites Comments on Major Revision to Cyber Supply Chain Risk Management Practices


Advertisement
Seeking HoNIST Opinions – NIST Invites Comments on Major Revision to Cyber Supply Chain Risk Management Practices for Systems and Organizations (SP 800-161) and Provides Further Software Supply Chain Guidance
Wednesday, May 26, 2021
The National Institute of Standards and Technology (“NIST”) is seeking comments on its draft NIST SP 800-161 Rev. 1, “Cyber Supply Chain Risk Management Practices for Systems and Organizations,” published on April 29, 2021. The public comment period currently is open and concludes on June 14, 2021. NIST anticipates releasing a second draft in September 2021, with a final version anticipated to be released by April 2022.
Primarily, the updates to NIST SP 800-161 are focused on helping organizations identify, assess, and respond to cyber supply chain risks while remaining aligned with other fundamental NIST cybersecurity risk management guidance. The revision to NIST SP 800-161 is designed to incorporate next generation cyber supply chain risk management (“C-SCRM”) controls, strategies, policies, plans, and risk assessments into broader enterprise risk management activities through the application of a multi-level approach. The ultimate goal of these major updates is to provide implementation guidance in a “more modular and consumable manner for acquirers, suppliers, developers, system integrators, external system service providers, and other information and communications technology (ICT)/operational technology (OT)-related service providers.”

Related Keywords

Jon Boyens , National Institute Of Standards , Guidance On Software Supply Chain Security , Communications Technology , Infrastructure Security Agency , Software Development Framework , Computer Security Division , Biden Administration , National Institute , Supply Chain Risk Management Practices , Inside Cybersecurity , Deputy Chief , Security Division , Supply Chain Information Sharing , Capability Implementation Measurement , Software Supply Chain , Against Software Supply Chain , Secure Software Development Framework , Supply Chain Lifecycle , Kaspersky Antivirus , Executive Order , தேசிய நிறுவனம் ஆஃப் தரநிலைகள் , தகவல்தொடர்புகள் தொழில்நுட்பம் , கணினி பாதுகாப்பு பிரிவு , தேசிய நிறுவனம் , விநியோகி சங்கிலி ஆபத்து மேலாண்மை ப்ர்யாக்டிஸஸ் , உள்ளே இணைய பாதுகாப்பு , துணை தலைமை , பாதுகாப்பு பிரிவு , மென்பொருள் விநியோகி சங்கிலி , பாதுகாப்பானது மென்பொருள் வளர்ச்சி கட்டமைப்பு , காஸ்பர்ஸ்கி வைரஸ் தடுப்பு , நிர்வாகி ஆர்டர் ,

© 2025 Vimarsana