Tool
NIST C-SCRM
NIST SP 800-161 guidance on cyber supply-chain risk management for acquiring and using ICT products.
Where it helps
- Govern Dependencies
Frames supply-chain risk as a graph of suppliers, components and processes—not isolated assets.