NIST icon
The Ultimate Guide to

NIST SP 800-161: Cyber Supply Chain Risk Management

What is NIST SP 800-161?

NIST SP 800-161, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, guides organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations. The publication integrates cybersecurity supply chain risk management (C-SCRM) into risk management activities by applying a multi-level approach that includes guidance on developing C-SCRM strategy implementation plans, C-SCRM policies, and risk assessments for products and services.

The current version of NIST SP 800-161 is Rev. 1, published in May 2022.

What are the benefits of NIST SP 800-161?

Organizations rely heavily on third-party vendors and suppliers to run their businesses, operate efficiently, and serve customers. Security issues in your supply chain can instantly become security risks for your organization. Supply chain risks often become magnified today because many organizations don’t have the processes and procedures to comprehensively manage supply chain risk.

NIST SP 800-161 can help organizations manage supply chain risk by delivering the following benefits:

  1. Enhanced supply chain security: By providing comprehensive guidelines for managing supply chain risks, organizations can better protect their systems from vulnerabilities and threats originating from their supply chain.
  2. Improved risk management: NIST SP 800-161 helps organizations identify, assess, and mitigate supply chain risks, leading to more robust risk management practices.
  3. Alignment with federal requirements: While not all organizations are required to comply with  NIST SP 800-161, it helps federal agencies and their contractors align with federal supply chain risk management standards and expectations.
  4. Increased trust and resilience: Implementing supply chain risk management practices enhances the overall trust and resilience of an organization’s information systems and operations.
  5. Competitive advantage: Demonstrating compliance with NIST SP 800-161 can provide a competitive edge in securing federal contracts and partnerships by showcasing a commitment to supply chain security.

What types of organizations does NIST SP 800-161 apply to?

Any organization sharing sensitive customer or patient information with third parties can benefit from following NIST SP 800-161 guidelines. For example:

  • Retail or e-commerce businesses storing sensitive customer information with card processors or cloud service providers
  • Healthcare organizations using email providers, coding services, or cloud storage vendors to assist in the storing or transmitting of sensitive patient records
  • Banking and financial service companies buying software products for marketing, accounting, or security services

How is  NIST SP 800-161 organized?

The introduction section of NIST SP 800-161 outlines the document’s purpose and target audience profiles. This section also discusses the methodology for building C-SCRM guidance using NIST SP 800-39, NIST SP 800-37, Rev 2, and NIST SP 800-53, Rev 5.

Section 2 builds a business case for C-SCRM and dives into the governance, organizational structures, roles, responsibilities, and activities performed across all three C-SCRM levels: enterprise, mission and business process, and operational. Section 2 also explains the integration of C-SCRM with the enterprise-wide risk management processes described in NIST SP 800-39, including the continuous and iterative steps of framing, assessing, responding to, and mitigating risk.

 Section 3 of NIST SP 800-161 provides an in-depth look at the critical success factors required for any C-SCRM program. This section discusses the integration of C-SCRM into acquisition, supply chain info sharing, awareness and training, key practices, implementing measurement controls, and dedicating resources to your C-SCRM program.

Appendix A covers C-SCRM security controls:

Access control

Supplier’s system access must be managed to prevent unauthorized release, modification, or destruction of information. Access should be limited only to the necessary type, duration, and level for authorized enterprises and monitored for impact on the supply chain.

Awareness and training

This family expands the Awareness and Training control of FIPS 200 to include C-SCRM. It discusses the training component behind understanding supply chain security challenges and the appropriate processes and controls to mitigate cybersecurity risk in the supply chain.

Audit and accountability

Information system audit records must be created and stored to monitor, investigate, and analyze unlawful or inappropriate system activity. This control also monitors and traces all system users’ actions.

Assessment, authorization, and monitoring

Information system controls must be assessed periodically to ensure correct function, and plans to correct any deficiencies and eliminate potential vulnerabilities must be developed and implemented. Information systems must also be continually monitored to ensure the effectiveness of controls.

Configuration management

Baseline configurations and inventories of information systems (e.g., hardware, software, firmware, documentation) must be established throughout the system development life cycle (SDLC). Additionally, security configuration settings must be created for all information system products.

Contingency planning

Guidelines must be created to establish and implement plans covering emergency response, backup operations, and post-disaster recovery for information systems and supply chains.

Identification and authentication

System components must be identified and authorized in addition to individuals and processes acting on behalf of individuals within the supply chain network. 

Incident response

Effective incident handling capability must be established within information systems and supply chains, including adequate preparation, detection, analysis, containment, recovery, and user response activities. All incidents must be tracked, documented, and reported to appropriate officials and authorities.

Maintenance

Maintenance must be performed on information systems while providing adequate controls for the tools, techniques, mechanisms, and personnel involved. C-SCRM should be applied to maintenance, including assessing cybersecurity risk in the supply chain, selecting C-SCRM controls, implementing these controls, and continued monitoring to ensure proper function. 

Media protection

Paper and digital media must be protected across the supply chain with access limited to authorized users. Additionally, all system media must be sanitized or destroyed before disposal.

Physical and environmental protection

Physical access to information systems, equipment, and operating environments must be limited to authorized personnel, while physical assets, infrastructure, and information systems within the supply chain must be safeguarded from environmental hazards.

Planning

Security plans must be developed, documented, implemented, and updated for supply chain information systems that describe current security controls and set the behavior guidelines for individuals accessing the systems.

Program management

Minimum security control requirements aren’t specified by FIPS 200 for program management. However, any program management controls should be applied in a C-SCRM context, providing guidance and feedback for enterprise-wide C-SCRM activities. These controls should apply across the entire enterprise while supporting an overarching information security program.

Personnel security

Ensures individuals in positions of responsibility meet established security criteria for those positions and protects supply chain information systems during personnel moves like terminations and transfers. Imposes formal sanctions for those failing to comply with personnel security policies.

Personally identifiable information processing and transparency

This is a new control family, explicitly developed to address the processing and transparency concerns of personally identifiable information (PII) within supply chains. Enterprises must build their PII processing and transparency policies and procedures with an eye on supply chain risk management and system security.

Risk assessment

Risk to organizational operations, assets, and individuals resulting from the operating of information systems must be periodically assessed in light of maintaining effective supply chain risk management.

System and service acquisition

Sufficient resources must be allocated to adequately secure organizational information systems and ensure all third-party suppliers follow similar protocols to protect the information, applications, products, and services outsourced from the company.

System and communications protection

Organizational communications must be monitored, controlled, and protected at both internal and external information system boundaries, employing architectural designs, software development techniques, and systems engineering principles to deliver adequate information security. 

System and information integrity

Teams must monitor information security alerts and take appropriate action to identify, report, and correct system flaws quickly. This includes protecting against malicious code at appropriate locations within information systems.

Supply chain risk management

FIPS 200 doesn’t specify minimum security requirements for supply chain risk management. NIST SP 800-53 Rev. 5 established this as a new control family with SP (800-161 R1), including all SR control enhancements from SP 800-53 Rev. 5 regarding supply chain risk management.

Appendix B lists the C-SCRM controls in NIST SP 800-161 and maps them to their corresponding NIST SP 800-53 controls as appropriate. 

Appendix C provides an example of a Risk Exposure Framework for C-SCRM that can help enterprises address potential and identified threats. The framework contains six examples that demonstrate how to identify vulnerabilities, describe specific threat sources, show the expected impact on the enterprise, and propose C-SCRM controls to help mitigate risk.

Appendix D provides examples of templates outlining the typical components of a C-SCRM strategy and implementation plan.

Appendix E augments the current content in NIST SP 800-161 and provides additional guidance specific to federal executive agencies on supply chain risk assessment factors, assessment documentation, risk severity levels, and risk response. 

Appendix F provides a link to a web portal for departments and agencies looking to facilitate compliance with Executive Order (EO) 14028, Improving the Nation’s Cybersecurity. 

Appendix G provides a detailed description of C-SCRM activities within the frame, assess, respond, and monitor steps of the risk management process. 

Appendices H through K provide a glossary, list of abbreviations, resources, and revision history.

What is NIST SP 800-161 compliance?

NIST SP 800-161 compliance means that an organization has implemented and follows the guidelines and best practices outlined in NIST SP 800-161 for supply chain risk management. This involves:

  • Identifying and assessing supply chain risks: The organization must identify potential risks throughout the supply chain that could impact the security, integrity, or availability of its information systems.
  • Implementing appropriate security controls to mitigate these risks: The organization must apply relevant security controls, often derived from NIST SP 800-53, and adapt them to address supply chain-specific risks, including controls related to procurement, development, and deployment processes.
  • Continuously monitoring and managing supply chain risks: The organization must establish ongoing monitoring and management practices to track and respond to changes in the supply chain that could introduce new risks.
  • Ensuring that supply chain partners also adhere to security requirements: The organization must ensure that its supply chain partners adhere to relevant security controls and practices, extending risk management beyond the organization’s immediate boundaries.

Compliance with NIST SP 800-161 demonstrates an organization’s commitment to securing its supply chain and protecting against threats and vulnerabilities that could impact its information systems.

Is NIST SP 800-161 compliance required?

NIST SP 800-161 compliance is not mandated across all industries, but is required for federal agencies and their contractors who need to manage supply chain risks. For federal agencies, adherence to NIST SP 800-161 is a key part of their supply chain risk management strategy. For organizations working with federal agencies, adhering to NIST SP 800-161 can be crucial for maintaining contracts and ensuring that supply chain risks are effectively managed.

What are the critical success factors for a supply chain risk management program?

Section 3 of NIST SP 800-161 documents the following six critical success factors to ensure program success:

  • Integrate C-SCRM with acquisition
  • Share supply chain information
  • Initiate C-SCRM Training and Awareness
  • Implementing foundational, sustaining, and enhancing practices
  • Measure the effectiveness of your C-SCRM program
  • Dedicate resources

NIST 800-161: Frequently Asked Questions

NIST SP 800-53 provides a catalog of security and privacy controls for federal information systems and organizations, with a focus on ensuring the integrity, confidentiality, and availability of information. NIST 800-53 is widely used across various sectors to guide the implementation of security controls and best practices.

NIST SP 800-161 extends the principles of NIST SP 800-53 by focusing specifically on Supply Chain Risk Management (SCRM). It provides guidelines for identifying, assessing, and mitigating risks within the supply chain and addressing the unique challenges associated with managing supply chain security, integrity, resilience, and trustworthiness.

NIST SP 800-53 provides a broad set of controls applicable to information systems, and NIST SP 800-161 applies these controls to the specific risks associated with supply chain management.

NIST SP 800-161 does not introduce entirely new control families but provides additional guidance and enhancements to the existing NIST SP 800-53 controls to address supply chain risk management. The supplementary guidance and control enhancements should be tailored to the unique risks facing the organization or program.

NIST SP 800-171 provides guidelines for protecting Controlled Unclassified Information (CUI) in non-federal systems. It outlines security requirements that are intended to ensure the confidentiality of CUI when it is processed, stored, or transmitted by non-federal entities, ensuring that organizations handling such information implement appropriate security measures.

NIST SP 800-161 is specifically concerned with supply chain risk management for federal information systems. While NIST SP 800-171 outlines requirements for protecting CUI, NIST SP 800-161 provides comprehensive guidance on managing risks associated with the supply chain, including the procurement, development, and deployment of information systems and services.

NIST 800-161 can significantly enhance your Cyber Supply Chain Risk Management (C-SCRM) or Third-Party Risk Management (TPRM) program by:

  1. Providing a structured approach: It offers a comprehensive framework for identifying, assessing, and mitigating supply chain risks.
  2. Enhancing risk visibility: By following NIST 800-161 guidelines, organizations can gain better visibility into their supply chain and third-party risks.
  3. Standardizing risk management practices: The guidelines help standardize risk management practices, making it easier to integrate supply chain risk management into broader risk management programs.
  4. Improving supplier relationships: By implementing best practices, organizations can foster stronger, more secure relationships with their suppliers and third-party partners.

Several tools can aid in achieving NIST 800-161 compliance, including:

  1. Compliance management solutions: Modern GRC platforms, like Hyperproof, combine compliance, risk assessment, and third-party risk management into one comprehensive solution. 
  2. Risk assessment tools: Software for conducting risk assessments can help identify and evaluate supply chain risks.
  3. Continuous monitoring solutions: These tools enable ongoing monitoring of supply chain activities and third-party vendors to detect and address potential risks in real-time.
  4. Document management systems: These systems help manage and maintain documentation related to compliance efforts, making it easier to demonstrate compliance during audits.
  5. Training and awareness programs: Tools that provide training and raise awareness about supply chain risks and compliance requirements ensure that all stakeholders are informed and engaged in the compliance process.

How Hyperproof Supports Cybersecurity Supply Chain Risk Management

Hyperproof’s compliance operations software helps organizations implement a robust cyber supply chain risk management program. Sign up for a personalized demo to see how you can use Hyperproof to manage a C-SCRM program efficiently.

NIST 800-161

Build a C-SCRM program based on the NIST SP 800-161 framework. The Hyperproof platform comes with this framework’s security controls out of the box.

Assign C-SCRM activities to process and control owners while keeping team members accountable.

Maintain a single database of all entities in your supply chain.

Conduct supplier or vendor risk assessments, analyze results, and prioritize risk mitigation activities.

Efficiently coordinate vendor remediation workflows and track the status of issues.

Easily map your C-SRM activities to requirements within regulatory frameworks and demonstrate compliance with no extra effort.

Document, organize, and centrally store all compliance artifacts, including C-SCRM policies, plans, risk assessment results, and remediation activities.

Save time retrieving compliance artifacts for audits.

Hyperproof partners with professional service firms with proven track records and deep expertise in helping organizations get NIST CSF ready. Our partners help customers design their compliance programs, build them out, and conduct readiness assessments to ensure there are no surprises when the audit occurs. If you need a referral, we’d love to talk.

Ready to see
Hyperproof in action?

G2Crowd Leader Enterprise
G2Crowd Leader Mid-Market
G2Crowd Users Love Us