NIST wants to the federal government to pay more attention to the supply chain
A federal IT standards body has moved to add key supply-chain provisions to its risk management guidance at a time of growing concern that Russian and Chinese companies pose a threat to national security. The National Institute of Standards and Technology on Wednesday released a draft update to its influential Risk Management Framework, which federal agencies use to assess cyber risk. The provisional update includes measures to guard against untrusted suppliers and the possibility of hackers slipping malicious code into the supply chain. Defining — let alone securing — all the components and systems that organizations get from third parties can be a struggle, according to the document. One answer, NIST says, is building “a chain of trust” with suppliers to ensure that each one of them provides adequate security protections for their products. The new measures are critical because of the globalized nature of the IT supply chain, according to NIST fellow Ron Ross, one of the publication’s authors. […]
The post NIST wants to the federal government to pay more attention to the supply chain appeared first on Cyberscoop.
Continue reading NIST wants to the federal government to pay more attention to the supply chain