Author: by the National Risk Management Center
The ICT Supply Chain Risk Management (SCRM) Task Force Small and Medium-sized Businesses (SMB) Working Group (WG) was created with the purpose of tailoring Task Force products to make them more applicable to SMBs which may find it difficult to institutionalize federal supply chain guidance due to limited finances, resources, and employees.
The ICT Supply Chain Risk Management (SCRM) Task Force Information Sharing Working Group (WG1) was created with the purpose of providing considerations about improving the sharing of supply chain risk information (SCRI) among the federal government and private industry to help mitigate threats to the nation’s ICT supply chain.
This CISA Insights provides a framework that government and private sector organizations (to include small and medium-sized businesses) outsourcing some level of IT support to MSPs can use to better mitigate against third-party risk.
CISA Announces Renewal of the Information and Communications Technology (ICT) Supply Chain Risk Management Task Force
This Toolkit—which includes strategic messaging, social media, videos, and resources—is designed to emphasize the role that we all have in securing information and communications technology (ICT) supply chains.
The Defending Against Software Supply Chain Attacks, released by CISA and the National Institute of Standards and Technology (NIST), provides an overview of software supply chain risks and recommendations on how software customers and vendors can use the NIST Cyber Supply Chain Risk Management (C-SCRM) Framework and the Secure Software Development Framework (SSDF) to identify, assess, and mitigate software supply chain risks.