Supply Chain Risk Management Practices for Federal Information Systems and Organizations

Supply Chain Risk Management Practices for Federal Information Systems and Organizations
复制标题

联邦信息系统和组织的供应链风险管理实践

DOI:
10.6028/nist.sp.800-161
复制
发表时间:
2015
期刊:
影响因子:
2.6
通讯作者:
Nadya Bartol
Nadya Bartol
中科院分区:
工程技术3区
文献类型:
--
作者:
Jon M. Boyens;Celia Paulsen;Rama S Moorthy;Nadya Bartol

文献摘要

被引文献

相似文献

联邦机构担心与信息和通信技术 (ICT) 产品和服务相关的风险,这些产品和服务可能包含潜在的恶意功能、假冒产品或由于 ICT 供应链内不良的制造和开发实践而容易受到攻击。这些风险与联邦机构对其所获得的技术的开发、集成和部署方式,以及用于确保产品和服务的完整性、安全性、弹性和质量的流程、程序和实践的可见性、理解和控制的降低有关。本出版物为联邦机构识别、评估和减轻其组织各级的 ICT 供应链风险提供指导。该出版物通过应用多层 SCRM 特定方法,将 ICT 供应链风险管理 (SCRM) 整合到联邦机构风险管理活动中,包括评估供应链风险和应用缓解活动的指南。
Federal agencies are concerned about the risks associated with information and communications technology (ICT) products and services that may contain potentially malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the ICT supply chain. These risks are associated with the federal agencies’ decreased visibility into, understanding of, and control over how the technology that they acquire is developed, integrated and deployed, as well as the processes, procedures, and practices used to assure the integrity, security, resilience, and quality of the products and services. This publication provides guidance to federal agencies on identifying, assessing, and mitigating ICT supply chain risks at all levels of their organizations. The publication integrates ICT supply chain risk management (SCRM) into federal agency risk management activities by applying a multitiered, SCRMspecific approach, including guidance on assessing supply chain risk and applying mitigation activities.