Cyber Supply Chain Risk Management (C-SCRM) focuses specifically on cybersecurity risks in supply chains. It addresses threats including malicious code inserted in software or hardware, compromised supplier access to organizational systems, data theft via supplier networks, and vulnerabilities introduced through third-party components. NIST SP 800-161 is the primary federal guidance document for C-SCRM.
C-SCRM is the part of supply chain risk management that deals with cybersecurity risk from suppliers, products and services, such as tampered hardware, malicious code in a software update, or a supplier's compromised access to your network.
NIST SP 800-161 Rev 1 is the main US government guidance on C-SCRM, and NIST SP 800-53 Rev 5 includes a dedicated Supply Chain Risk Management (SR) control family. A C-SCRM program usually covers supplier risk assessments, security requirements in contracts, component provenance and monitoring of critical suppliers.
In the SCF, these controls sit mainly in Third-Party Management (TPM), with related controls in Technology Development and Acquisition (TDA) and Asset Management (AST).