MLchartDataset catalogue

Supply chain risk management (SCRM)

Term · Cybersecurity · MLC-T-CYB-004140

1. A systematic process for managing supply chain risk by identifying susceptibilities, vulnerabilities, and threats throughout the supply chain and developing mitigation strategies to combat those threats whether presented by the supplier, the supplied product and its sub-elements, or the supply chain (e.g., initial production, packaging, handling, storage, transport, mission operation, and disposal).

2. The process of identifying, assessing, and mitigating the risks associated with the global and distributed nature of information and communications technology product and service supply chains.

3. A systematic process for managing cyber supply chain risk exposures, threats, and vulnerabilities throughout the supply chain and developing risk response strategies to the risks presented by the supplier, the supplied products and services, or the supply chain.

4. the implementation of processes, tools or techniques to minimize the adverse impact of attacks that allow the adversary to utilize implants or other vulnerabilities inserted prior to installation in order to infiltrate data, or manipulate information technology hardware, software, operating systems, peripherals (information technology products) or services at any point during the life cycle.

Table 1. Record
IdentifierMLC-T-CYB-004140
FieldCybersecurity
AbbreviationSCRM
ReferencesCNSSI 4009-2022 from CNSSD No. 505; CNSSI 4009-2022 from OMB Circular A-130 (2016); NIST SP 800-18r2 from OMB Circular A-130 (2016); NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5; NISTIR 8074 Vol. 2; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-004140",
  "term": "Supply chain risk management (SCRM)",
  "field": "Cybersecurity",
  "definition": "1. A systematic process for managing supply chain risk by identifying susceptibilities, vulnerabilities, and threats throughout the supply chain and developing mitigation strategies to combat those threats whether presented by the supplier, the supplied product and its sub-elements, or the supply chain (e.g., initial production, packaging, handling, storage, transport, mission operation, and disposal).\n\n2. The process of identifying, assessing, and mitigating the risks associated with the global and distributed nature of information and communications technology product and service supply chains.\n\n3. A systematic process for managing cyber supply chain risk exposures, threats, and vulnerabilities throughout the supply chain and developing risk response strategies to the risks presented by the supplier, the supplied products and services, or the supply chain.\n\n4. the implementation of processes, tools or techniques to minimize the adverse impact of attacks that allow the adversary to utilize implants or other vulnerabilities inserted prior to installation in order to infiltrate data, or manipulate information technology hardware, software, operating systems, peripherals (information technology products) or services at any point during the life cycle.",
  "abbreviation": "SCRM",
  "references": [
    "CNSSI 4009-2022 from CNSSD No. 505",
    "CNSSI 4009-2022 from OMB Circular A-130 (2016); NIST SP 800-18r2 from OMB Circular A-130 (2016); NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016)",
    "NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5",
    "NISTIR 8074 Vol. 2",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/supply-chain-risk-management-scrm/"
}

Record 4,118 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.