Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 1326 (Initial Public Draft)

NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide

Date Published: October 30, 2024
Comments Due: December 16, 2024 (public comment period is CLOSED)
Email Questions to: scrm-nist@nist.gov

Author(s)

National Institute of Standards and Technology

Announcement

Supply chain risk assessments start with due diligence. Acquirers who make procurement decisions need to be informed about potential supplier risks before those decisions are executed. Consequently, many acquisition operating procedures strongly recommend or even require an assessment of a supplier’s risk prior to entering into an agreement with them.

Based on the widely adopted content in NIST Special Publication (SP) 800-161r1, this new draft Quick-Start Guide proposes an implementation-ready approach to conducting the minimum amount of investigative rigor on potential suppliers. Identifying the primary risk factors that an acquirer should consider can enable quick turnarounds with limited resources. 

Abstract

Keywords

cybersecurity supply chain risk management; due diligence; C-SCRM; risk assessment; information and communications technology; ICT; quick-start guide
Control Families

Risk Assessment; Supply Chain Risk Management

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.1326.ipd
Download URL

Supplemental Material:
NIST C-SCRM Project

Document History:
10/30/24: SP 1326 (Draft)

Topics

Security and Privacy

cybersecurity supply chain risk management, risk assessment

Activities and Products

quick-start guides