Supply Chain Risk Management Practices for Federal Information Systems and Organizations
Supply Chain Risk Management Practices for Federal Information Systems and Organizations
复制标题
联邦信息系统和组织的供应链风险管理实践
DOI:
10.6028/nist.sp.800-161
复制
发表时间:
2015
影响因子:
2.6
通讯作者:
Nadya Bartol
中科院分区:
文献类型:
--
作者:
Jon M. Boyens;Celia Paulsen;Rama S Moorthy;Nadya Bartol
Federal agencies are concerned about the risks associated with information and communications technology (ICT) products and services that may contain potentially malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the ICT supply chain. These risks are associated with the federal agencies’ decreased visibility into, understanding of, and control over how the technology that they acquire is developed, integrated and deployed, as well as the processes, procedures, and practices used to assure the integrity, security, resilience, and quality of the products and services. This publication provides guidance to federal agencies on identifying, assessing, and mitigating ICT supply chain risks at all levels of their organizations. The publication integrates ICT supply chain risk management (SCRM) into federal agency risk management activities by applying a multitiered, SCRMspecific approach, including guidance on assessing supply chain risk and applying mitigation activities.