B08_Solicitation_Attachment_5_IA_Cybersecurity_-_Supply_Chain_Risk_Management_Guidelines.pdf
PDF 315 KB Posted
- Attached to
- IT Support Services (ITSS) IDIQ Federal contract opportunity
- Solicitation number
- 140A1624R0001
About this file
This document outlines a Cybersecurity Supply Chain Risk Management (C-SCRM) plan for the Bureau of Indian Affairs. The plan establishes the Bureau's approach to implementing C-SCRM practices across its information systems portfolio in accordance with guidelines from the Department of the Interior. It defines the Bureau's organizational structure and key objectives for C-SCRM, provides an overview of its information systems, and establishes roles and responsibilities for C-SCRM functions. The document also includes a self-assessment of the Bureau's current level of implementation for foundational, sustaining, and enhancing C-SCRM practices defined by NIST. Finally, it outlines high-level implementation plans and milestones for achieving six objectives related to integrating C-SCRM practices within the Bureau's acquisition process, training programs, tooling, and risk reporting.
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
This Document Contains Controlled Unclassified Information (CUI)
Indian Affairs FY 2024 Cybersecurity – Supply Chain
Risk Management Plan
Version 0.4 October 31, 2023
U.S. Department of the Interior Indian Affairs
Office of Information Management Technology
Cybersecurity – Supply Chain Risk Management Plan
This Document Contains Controlled Unclassified Information (CUI) i
Document Approval
Associate Chief Information Officer (ACIO) Date Assistant Secretary - Indian Affairs (AS-IA)
Head of Contracting Activity Date Assistant Secretary - Indian Affairs (AS-IA)
This Document Contains Controlled Unclassified Information (CUI) ii
Revision History
Author Version Revision Date Revision Summary
Virgilio Rodriguez 0.1 8/8/23 Initial creation and edits.
Mark Tanno 0.2 10/26/23 Reformatted to standard OIT template and proofread.
Virgilio Rodriguez 0.3 10/3/23 Shortened Topics and changed acronyms Tom Hoyler 0.4 10/31/23 Received on 10/30 for review.
Added comments and recommended edits for consideration. Removed all references to OIT/OIMT being document owner.
Virgilio Rodriguez 0.5 11/01/23 Removed table, added acronyms and added roles and responsibilities
This Document Contains Controlled Unclassified Information (CUI) iii
Table of Contents
1.0 Introduction
1.1 Document Purpose
1.2 Authority
1.3 Intended Audience
1.4 Revisions and Maintenance
2.0 Organizational Approach to C-SCRM
2.1 Organizational Overview
2.2 Key Objectives
2.3 Information Systems Overview
2.4 Roles and Responsibilities
2.5 Assumptions
2.6 Constraints
2.7 Critical Success Factors
2.8 Tools and Technologies
3.0 C-SCRM Key Practices
3.1 C-SCRM Key Practices – Level of Implementation (LOI) Self-Assessment
4.0 High-Level Implementation Plans and Progress Tracking
Glossary/Acronyms
References and Related Publications
C-SCRM Key Practices Reference
This Document Contains Controlled Unclassified Information (CUI) iv
List of Tables Table 1: Practice Groups Table 2: Objectives Table C-1: Foundational Practices Table C-2: Sustaining Practices Table C-3: Enhancing Practices
This Document Contains Controlled Unclassified Information (CUI)
1.0 Introduction
The Bureau of Indian Affairs develops, operates, and maintains multiple information systems to perform its mission and deliver critical services to the public; other Federal departments and agencies; and state, local, tribal, and territorial governments across the nation. The Information and Communications Technology and Operational Technology (ICT/OT) products and services used by these systems rely upon an extensive, complex, globally distributed, and interconnected supply chain ecosystem that is long, has geographically diverse routes, and consists of multiple tiers of outsourcing.
1.1 Document Purpose
This document outlines the high-level strategy and plans for the Bureau of Indian Affairs Cybersecurity Supply Chain Risk Management (C-SCRM) efforts and forms the basis for Indian Affairs (IA) C-SCRM program. The strategy applies to Bureau of Indian Affairs ICT and OT environments, inclusive of Internet of Things (IoT) technologies. The Bureau of Indian Affairs views C-SCRM as a critical component of the organization’s Cybersecurity Risk Management (CRM) program, which is a critical component of the Department’s Enterprise Risk Management (ERM) program.
The C-SCRM program emphasizes risk management from the organization level down through the systems-level including “controls compliance.” The Bureau of Indian Affairs C-SCRM program and associated capabilities will evolve over time to create a supply chain risk posture that enhances the overarching enterprise cybersecurity risk posture and enables senior leadership’s oversight of and visibility into C-SCRM activities.
1.2 Authority
Creation of SCRM programs within Federal departments was mandated under the following Acts, Executive Orders, and legislation that deem critical the need to protect the supply chain of components that may comprise the Information Technology (IT) enterprises of the United States Government.
The DOI C-SCRM Policy for ICT Products and Services provides overall guidance.
OCIO_PAM Memo_C-SCRM Policy for ICT Products and Services_Signed 05312023.pd
1.3 Intended Audience
This document is intended for use by Bureau of Indian Affairs employees and contractors involved in functions associated with acquiring, engineering, developing, testing, deploying, operating, maintaining, and retiring ICT/OT components and systems. These functions include but are not limited to information technology, information security, contracting, risk executives, program management, legal, supply chain and logistics, acquisition and procurement, system owners, and any other related functions.
https://doimspp.sharepoint.com/:b:/r/sites/ocio-Policy-Portal/Policies/OCIO_PAM%20Memo_C-SCRM%20Policy%20for%20ICT%20Products%20and%20Services_Signed%2005312023.pdf?csf=1&web=1&e=gFssZG https://doimspp.sharepoint.com/:b:/r/sites/ocio-Policy-Portal/Policies/OCIO_PAM%20Memo_C-SCRM%20Policy%20for%20ICT%20Products%20and%20Services_Signed%2005312023.pdf?csf=1&web=1&e=gFssZG
This Document Contains Controlled Unclassified Information (CUI)
1.4 Revisions and Maintenance
Criteria that may trigger revisions include but are not limited to changes of policies that impact the C-SCRM strategy and implementation.
• significant strategy and implementation events;
• introduction of new technologies; discovery of new vulnerabilities;
• operational or environmental changes; and
• shortcomings in the strategy and implementation plan; change of scope; and other Bureau of Indian Affairs-specific criteria.
This Document Contains Controlled Unclassified Information (CUI)
2.0 Organizational Approach to C-SCRM
This plan describes the anticipated implementation of supply chain risk management within a subsection of the Indian Affairs (IA) organization (which includes AS-IA), Bureau of Indian Affairs (BIA), and Bureau of Indian Education (BIE), and reflects the programs, policies and procedures that will provide both a strategic and tactical framework for improving the supply chain risk management efforts.
2.1 Organizational Overview
AS-IA Mission: To assist and support the Secretary of the Interior in fulfilling the United States’ trust responsibility to the Federally recognized American Indian and Alaska Native tribes and villages and individual Indian trust beneficiaries, as well as in maintaining the Federal-Tribal government-to-government relationship.
BIA Mission: To enhance the quality of life, to promote economic opportunity, and to carry out the responsibility to protect and improve the trust assets of American Indians, Indian tribes, and Alaska Natives.
BIE Mission: To provide quality education opportunities from early childhood through life in accordance with the Tribes' needs for cultural and economic well-being in keeping with the wide diversity of Indian Tribes and Alaska Native Villages as distinct cultural and governmental entities. The Bureau considers the whole person (spiritual, mental, physical and cultural aspects).
Office of Information Technology and Acquisitions will work together to deliver information solutions to empower Indian Affairs programs to fulfill their commitments to Indian Country.
2.2 Key Objectives
• The Bureau of Indian Affairs will ensure at the procurement or acquisition phase that the vendor or service provider must adhere to current policies, guidelines, and mandated.directives.
• The entire organization will spread awareness of the supply chain risk incidents and processes as part of users’ annual training, so purchases are always made through the required vetting process.
• The organization will integrate SCRM into incident response, threat-informed security program, disaster recovery, and helpdesk reporting system.
• The organization will conduct supply chain risk assessments, review results and lessons learned, and share them with all stakeholders for awareness.
• The organization will leverage C-SCRM tools managed by the Department in day-to-day activities.
• The organization will generate reports or metrics of supply chain risks that were identified, tracked, and mitigated to upper management.
This Document Contains Controlled Unclassified Information (CUI)
2.3 Information Systems Overview
The Bureau of Indian Affairs systems are a combination of on-premises and cloud configurations. They provide a variety of functions and services:
• hosting servers and network equipment;
• enterprise services;
• education learning systems;
• financial assistance systems;
• transportation information systems;
• law enforcement systems;
• irrigation information systems;
• student information systems;
• geospatial systems;
• timber sales accounting system;
• trust accountability tracking system;
• oil, gas, energy, and mineral system;
• loan management systems;
• trust asset and accounting systems;
• budget planning system;
• accountability performance system;
• enrolment reporting and payment system;
• dam safety and environmental systems; and
• electric utility management systems.
For more detailed information on systems’ functions and capabilities, please refer to BisonGRC.
2.4 Roles and Responsibilities
Roles and Responsibilities
Mission/Business Practices:
Authorizing Official (AO)
This Document Contains Controlled Unclassified Information (CUI)
The AO develops mission and business process strategy. Manages risks within mission and business processes.
Associate Chief Information Officer (ACIO) The ACIO develops mission and business process strategy. Manages risks within mission and business processes. Develops mid-level policies and procedures, guidance and constraints.
Head of Contracting Activity (HCA) The HCA develops mission and business process strategy. Manages risks within mission and business processes. Develops mid-level policies and procedures, guidance and constraints. Reduces vulnerabilities at the onset of new IT projects and/or related acquisitions.
Associate Chief Information Security Officer (ACISO) The ACISO manages risks within mission and business processes. Develops mid-level policies and procedures, guidance and constraints.
Information Systems Security Manager (ISSM) The ISSM tailors the enterprise risk framework to the mission and business process.
Reviews and assesses system, human, or organizational flaws that expose business, technical, and acquisition environments to cyber threats and attacks. Collaborates with the C-SCRM WG and OCIO Enterprise Cyber Risk Management Team to facilitate C- SCRM activities.
Information Systems Security Officer (ISSO) The ISSO tailors the enterprise risk framework to the mission and business process.
Reviews and assesses system, human, or organizational flaws that expose business, technical, and acquisition environments to cyber threats and attacks. Collaborates with the C-SCRM WG and OCIO Enterprise Cyber Risk Management Team to facilitate C- SCRM activities.
Project Manager (PM) The PM collaborates with the C-SCRM WG and OCIO Enterprise Cyber Risk Management Team to facilitate C-SCRM activities.
Research and Development Engineers The R&D Engineers review and assess system, human, or organizational flaws that expose business, technical, and acquisition environments to cyber threats and attacks.
Reduce vulnerabilities at the onset of new IT projects and/or related acquisitions.
Collaborate with the C-SCRM WG and OCIO Enterprise Cyber Risk Management Team to facilitate C-SCRM activities.
The Acquisitions and Supplier Relationship Management and cost accounting personnel reduce vulnerabilities at the onset of new IT projects and/or related acquisitions. Collaborate with the C-SCRM WG and OCIO Enterprise Cyber Risk Management Team to facilitate C-SCRM activities.
This Document Contains Controlled Unclassified Information (CUI)
Operational:
System Owners Implement C-SCRM policies. Adhere to guidance and constraints provided by Level 1 and Level 2. Tailor C-SCRM to the context of the individual system and apply it throughout the system life cycle. Report on C-SCRM to Level 2.
System Administrators Implement C-SCRM policies. Adhere to guidance and constraints provided by Level 1 and Level 2. Tailor C-SCRM to the context of the individual system and apply it throughout the system life cycle. Report on C-SCRM to Level 2.
Network Administrators Implement C-SCRM policies. Adhere to guidance and constraints provided by Level 1 and Level 2. Tailor C-SCRM to the context of the individual system and apply it throughout the system life cycle. Report on C-SCRM to Level 2.
Contracting personnel Implement C-SCRM policies. Adhere to guidance and constraints provided by Level 1 and Level 2. Tailor C-SCRM to the context of the individual system and apply it throughout the system life cycle. Report on C-SCRM to Level 2.
2.5 Assumptions
Highlight any key assumptions associated with the Bureau/office C-SCRM program.
The department will acquire and provide training and access to C-SCRM tools to Bureau personnel. Strictly adhering to C-SCRM principles and guidance will dramatically impact Bureau processes and start us on a path towards maturity.
2.6 Constraints
Highlight any key constraints associated with the Bureau/office C-SCRM program.
The Bureau/office may not find the appropriate personnel/staff or funding to get involved with C-SCRM initiative.
2.7 Critical Success Factors
Identify any critical success factors associated with the Bureau/office C-SCRM program and identify any strategies, plans, and activities to address them.
C-SCRM related incidents will be reduced as a result of implementing a thorough and inclusive C-SCRM initiative.
This Document Contains Controlled Unclassified Information (CUI)
2.8 Tools and Technologies
Identify any specific tools and technologies used by the Bureau/office in performing C- SCRM, such those used in performing criticality analysis, identifying and documenting supply chain participants, performing supplier/product/service risk assessments, monitoring and alerting on supplier risks and statuses, etc.
Sample: To be determined.
This Document Contains Controlled Unclassified Information (CUI)
3.0 C-SCRM Key Practices
Level of Implementation (LOI) Self-Assessment: perform a self-assessment of Bureau/office implementation of C-SCRM key practices (per NIST 800-161r1) using the provided table or form (see below). For each practice listed, assess the LOI using the provided scale.
1. Ad Hoc
2. Defined
3. Consistently Implemented
4. Managed and Measurable
5. Optimized).
3.1 C-SCRM Key Practices – Level of Implementation (LOI) Self- Assessment
Level of Implementation (LOI) Self-Assessment Level of implementation (LOI) assessments for C-SCRM Key Practices should be made based on the following scale.
1. (Ad-hoc): Practices are not formalized; activities are performed in an ad-hoc, reactive manner.
2. (Defined): Practices are formalized and documented, but not consistently implemented.
3. (Consistently Implemented): Practices are consistently implemented, but quantitative and qualitative effectiveness measures are lacking.
4. (Managed and Measurable): Quantitative and qualitative measures on the effectiveness of practices are collected across the organization and used to assess them and make necessary changes.
5. (Optimized): Practices are fully institutionalized, repeatable, self-generating, consistently implemented, and regularly updated based on changing threats, technology landscape, and business or mission needs.
Additional details on the C-SCRM Key Practices may be viewed in the Appendix C.
Table 1: Practice Groups
# Practice Group Practice LOI (1-5) F/1 Foundational Establish a C-SCRM PMO/Team 2
F/2 Foundational Obtain leadership support for C-
SCRM.
F/3 Foundational Implement a risk management hierarchy and process.
This Document Contains Controlled Unclassified Information (CUI)
F/5 Foundational Develop process for criticality assessment.
F/6 Foundational Establish a C-SCRM aware culture. 1 F/7 Foundational Integrate C-SCRM into acquisition and procurement policies and procedures.
F/9 Foundational Use a supplier risk assessment process on a prioritized basis.
F/10 Foundational Implement a quality and reliability program.
F/11 Foundational Establish explicit roles for C-
SCRM.
F/12 Foundational Ensure adequate resources are allocated.
F/13 Foundational Ensure cleared personnel are engaged.
F/14 Foundational Establish baseline controls for C-
SCRM.
F/15 Foundational Establish checks and balances. 1 F/16 Foundational Establish a supplier management program.
F/17 Foundational Integrate C-SCRM into incident management program and processes.
F/18 Foundational Establish processes for suppliers and providers to disclose product vulnerabilities.
F/19 Foundational Establish capability for managing and monitoring components of software.
S/1 Sustaining Integrate C-SCRM into a threat-informed security program.
S/2 Sustaining Use third-party assessments, site visits, and formal certification.
S/3 Sustaining Establish a formal supplier monitoring program.
S/5 Sustaining Establish a formalized information sharing processes (e.g., with ISACs, FASC, etc.).
S/6 Sustaining Regularly report C-SCRM risks to executives and risk committees.
S/7 Sustaining Establish a formal C-SCRM training program.
S/8 Sustaining Integrate C-SCRM into SDLC. 1 S/9 Sustaining Integrate C-SCRM into contractual agreements.
This Document Contains Controlled Unclassified Information (CUI)
S/10 Sustaining Suppliers participate in incident response, disaster recovery, contingency planning.
S/11 Sustaining Collaborate with suppliers to improve their cybersecurity practices.
S/12 Sustaining Establish formally defined, collected, and reported C-SCRM metrics.
E/1 Enhancing Leverage tools for automating C- SCRM processes.
E/2 Enhancing Use quantitative risk analyses techniques.
E/3 Enhancing Apply predictive and adaptive C- SCRM strategies and processes.
E/4 Enhancing Establish or participate in community of practice.
This Document Contains Controlled Unclassified Information (CUI)
4.0 High-Level Implementation Plans and Progress Tracking
For the key objectives summarized earlier, identify specific activities and milestones targeted toward achieving each objective using a table such as the one below. For each activity or milestone, provide a numeric identifier (e.g., 1, 2, 3), summarize the activity or milestone, state the current status (e.g., Not Started, In Process, Completed), identify the responsible owner (i.e., role or individual), define a priority (e.g., H, M, L), and identify the general timeframe for completing.
Example:
Objective #1: State the key objective.
Table 2: Objectives
# Activity/Milestone Status Owner Priority Timeframe 1 The organization will ensure at the procurement or acquisition phase that the vendor or service provider must adhere to current policies, guidelines, and directives.
Not Started Acquisitions 1 FY25
2 The entire organization will spread awareness of the supply chain risk incidents and processes as part of user’s annual training
Not Started Acquisitions, OIT
1 FY25
3 The organization will integrate supply chain risk management into an incident response, threat-informed security program, disaster recovery and Help Desk reporting system.
Not Started OIT 1 FY25
4 The organization will conduct supply chain risk assessments, review results and lessons learned, and share them with all stakeholders for awareness.
Not Started (Will be on Rev 5)
OIT 2 FY25
5 The organization will leverage C-SCRM tools managed by the Department in day-to-day activities.
Not Started (Pilot is upcoming)
Acquisitions, OIT
2 FY25
This Document Contains Controlled Unclassified Information (CUI)
# Activity/Milestone Status Owner Priority Timeframe 6 The organization will generate reports or metrics of supply chain risks that were identified, tracked, and mitigated to upper management.
Not Started Acquisitions, OIT
2 FY25
This Document Contains Controlled Unclassified Information (CUI)
Glossary/Acronyms C-SCRM – Cybersecurity Supply Chain Risk Management
ICT/OT - Internet Communication Technology/Operational Technology
BisonGRC (Xacta) – Bison Governance Risk Compliance
This Document Contains Controlled Unclassified Information (CUI)
References and Related Publications https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf Cybersecurity (sharepoint.com) DOI Enterprise Cybersecurity Risk Management Strategy DOI Enterprise Information Security Continuous Monitoring Strategy (New) DOI IT Supply Chain Risk Management Strategy DOI IT Supply Chain Identification and Documentation DOI IT Supply Chain Risk Assessment Memo - Mandatory Use of Supplier Risk Questionnaire during Contractor Responsibility Determination for Major Information Technology Investments Supplier Risk Questionnaire V1.4 DOI IT Counterfeit Detection Reference Guide https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://doimspp.sharepoint.com/sites/doi-imt-services/SitePages/Cybersecurity.aspx?xsdata=MDV8MDF8fDFlNTEwYTVkNzQwMjQyYzRkMGI4MDhkYmQ2NjMzYjMyfDA2OTNiNWJhNGIxODRkN2I5MzQxZjMyZjQwMGE1NDk0fDB8MHw2MzgzMzk0OTM4ODY1MDU3Mzl8VW5rbm93bnxWR1ZoYlhOVFpXTjFjbWwwZVZObGNuWnBZMlY4ZXlKV0lqb2lNQzR3TGpBd01EQWlMQ0pRSWpvaVYybHVNeklpTENKQlRpSTZJazkwYUdWeUlpd2lWMVFpT2pFeGZRPT18MXxMMk5vWVhSekx6RTVPakZoTm1Fd09XTXpMV00zWWpRdE5EYzVaaTA1TlRBeExXRmpZV1F3WkdKa01tRmxObDloTXpBNE5tRTJOUzAwTjJWa0xUUXlNalV0T0dRd1l5MWhaR1JpTmpJeFlUUTJORGRBZFc1eExtZGliQzV6Y0dGalpYTXZiV1Z6YzJGblpYTXZNVFk1T0RNMU1qVTROamswTVE9PXxjYWEyZTUyZjM3NGM0YjVmZDBiODA4ZGJkNjYzM2IzMnw5MmE1YTViMWU1ZTk0NWU4OGYwYzNkMTM3ODRkMmRhNQ%3D%3D&sdata=ZXgyU2xXbTNqemVTMU82TkI5eE9oOWg3aVZVd1pOT0JkeVljU3l6ZUdYaz0%3D&ovuser=0693b5ba-4b18-4d7b-9341-f32f400a5494%2Cmark.tanno%40indianaffairs.gov https://doimspp.sharepoint.com/:b:/r/sites/doi-imt-services/Shared%20Documents/Cybersecurity/DOI-Enterprise%20Cybersecurity%20Risk%20Management%20Plan_Signed.pdf?csf=1&web=1&e=jxcxxkhttps%3a//doimspp.sharepoint.com/%3ab%3a/r/sites/doi-imt-services/Shared%20Documents/Cybersecurity/DOI-Enterprise%20Cybersecurity%20Risk%20Management%20Plan_Signed.pdf?csf=1&web=1&e=jxcxxk https://doimspp.sharepoint.com/:b:/r/sites/doi-imt-services/Shared%20Documents/Cybersecurity/DOI%20E-ISCM%20Strategy%20-%20V1%20-%2020230530-singed.pdf?csf=1&web=1&e=nWKXlt https://doimspp.sharepoint.com/:b:/r/sites/doi-imt-services/Shared%20Documents/Cybersecurity/DOI-ICT%20Supply%20Chain%20Risk%20Management%20Strategy_SCRM_V1.0%20signed.pdf?csf=1&web=1&e=bTLyoq https://doimspp.sharepoint.com/:b:/r/sites/doi-imt-services/Shared%20Documents/Cybersecurity/DOI-ICT%20Suppy%20Chain%20Identification%20and%20Mapping_V1.0%20signed.pdf?csf=1&web=1&e=TqGpUP https://doimspp.sharepoint.com/:b:/r/sites/doi-imt-services/Shared%20Documents/Cybersecurity/DOI-ICT%20Suppy%20Chain%20Risk%20Assessment_V1.0-signed.pdf?csf=1&web=1&e=LgiC7w https://doimspp.sharepoint.com/sites/doi-imt-services/Shared%20Documents/Forms/AllItems.aspx?id=/sites/doi-imt-services/Shared%20Documents/Cybersecurity/OCIO%20Memo_Mandatory%20Use-SRQ-Contractor%20Resp%20Determination%20FINAL.pdf&parent=/sites/doi-imt-services/Shared%20Documents/Cybersecurity https://doimspp.sharepoint.com/sites/doi-imt-services/Shared%20Documents/Forms/AllItems.aspx?id=/sites/doi-imt-services/Shared%20Documents/Cybersecurity/OCIO%20Memo_Mandatory%20Use-SRQ-Contractor%20Resp%20Determination%20FINAL.pdf&parent=/sites/doi-imt-services/Shared%20Documents/Cybersecurity https://doimspp.sharepoint.com/sites/doi-imt-services/Shared%20Documents/Forms/AllItems.aspx?id=/sites/doi-imt-services/Shared%20Documents/Cybersecurity/Supplier%20Risk%20Questionnaire%20V%201.4.pdf&parent=/sites/doi-imt-services/Shared%20Documents/Cybersecurity https://doimspp.sharepoint.com/:b:/r/sites/doi-imt-services/Shared%20Documents/Cybersecurity/DOI-ICT%20Counterfeit%20Detection%20Reference%20Guide%20-%20V1.0%20-%2020220527.pdf?csf=1&web=1&e=XZAYEC
This Document Contains Controlled Unclassified Information (CUI)
C-SCRM Key Practices Reference The Department’s C-SCRM efforts will be based upon standardized practices across multiple disciplines and an evolving set of C-SCRM capabilities. The guidance provided in NIST SP 800-161r1 describes a set of C-SCRM Key Practices for enterprises to consider and prioritize in implementation to achieve a base-level of maturity prior to advancing on to additional C-SCRM capabilities.
NIST categorizes the C-SCRM Key Practices into three groups, including Foundational, Sustaining, and Enhancing, in support of the following outcomes:
• Integrating C-SCRM across the enterprise;
• Establishing a formal program;
• Knowing and managing critical products, services, and suppliers;
• Understanding an enterprise’s supply chain;
• Closely collaborating with critical suppliers;
• Including critical suppliers in resilience and improvement activities;
• Assessing and monitoring throughout the supplier relationship; and
• Planning for the full life cycle.
This Appendix summarizes C-SCRM Key Practices for ease of reference and assigns each a unique alphanumeric identifier derived from the categorization (i.e., F=Foundational, S=Sustaining, and E=Enhancing) and sequence (e.g., 1, 2, 3, 4) in NIST SP 800-161r1. This approach to standardizing references will facilitate planning and tracking of progress across the enterprise as the Department’s C-SCRM capabilities evolve and mature over time.
Foundational Practices The following are specific examples of the recommended multidisciplinary foundational practices that can be incrementally implemented to improve an enterprise’s ability to develop and execute more advanced C-SCRM practices.
Table C-1: Foundational Practices
# Practice F/1 Establish a C-SCRM PMO/Team.
Establish a core, dedicated, multidisciplinary C-SCRM Program Management Office and/or C-SCRM team.
F/2 Obtain leadership support for C-SCRM.
Obtain senior leadership support for establishing and/or enhancing C-SCRM.
F/3 Implement a risk management hierarchy and process.
This Document Contains Controlled Unclassified Information (CUI)
# Practice Implement a risk management hierarchy and risk management process (in accordance with NIST SP 800-39, Managing Information Security Risk [NIST SP 800-39]), including an enterprise-wide risk assessment process (in accordance with NIST SP 800-30, Rev. 1, Guide for Conducting Risk Assessments [NIST SP 800-30 Rev. 1]).
F/4 Establish a C-SCRM governance structure.
Establish an enterprise governance structure that integrates C-SCRM requirements and incorporates these requirements into the enterprise policies.
F/5 Develop a process for criticality assessment.
Develop a process for identifying and measuring the criticality of the enterprise’s suppliers, products, and services.
F/6 Establish a C-SCRM aware culture.
Raise awareness and foster understanding of what C-SCRM is and why it is critically important.
F/7 Integrate C-SCRM into acquisition and procurement policies and procedures.
Develop and/or integrate C-SCRM into acquisition and procurement policies and procedures (including Federal Information Technology Acquisition Reform Act [FITARA] processes, applicable to federal agencies) and purchase card processes. Supervisors and managers should also ensure that their staff aims to build C-SCRM competencies.
F/8 Establish process for determining FIPS 199 impact levels.
Establish consistent, well-documented, repeatable processes for determining Federal Information Processing Standards (FIPS) 199 impact levels.
F/9 Use supplier risk assessment process on a prioritized basis.
Establish and begin using supplier risk-assessment processes on a prioritized basis (inclusive of criticality analysis, threat analysis, and vulnerability analysis) after the [FIPS 199] impact level has been defined.
F/10 Implement quality and reliability program.
Implement a quality and reliability program that includes quality assurance and quality control process and practices.
F/11 Establish explicit roles for C-SCRM.
Establish explicit collaborative and discipline-specific roles, accountabilities, structures, and processes for supply chain, cybersecurity, product security, physical security, and other relevant processes (e.g., Legal, Risk Executive, HR, Finance, Enterprise IT, Program Management and System Engineering, Information Security, Acquisition and Procurement, Supply Chain Logistics, etc.).
F/12 Ensure adequate resources are allocated.
Ensure adequate resources are dedicated and allocated to information security and C-SCRM to ensure proper implementation of policy, guidance, and controls.
F/13 Ensure cleared personnel are engaged.
Ensure sufficient cleared personnel with key C-SCRM roles and responsibilities access and share C-SCRM-related classified information.
F/14 Establish baseline controls for C-SCRM.
This Document Contains Controlled Unclassified Information (CUI)
# Practice Implement an appropriate and tailored set of baseline information security controls found in NIST SP 800-53, Revision 5, Security and Privacy Controls for Information Systems and Enterprises [NIST SP 800-53, Rev. 5].
F/15 Establish checks and balances.
Establish internal checks and balances to ensure compliance with security and quality requirements.
F/16 Establish a supplier management program.
Establish a supplier management program that includes, for example, guidelines for purchasing from qualified Original Equipment Manufacturers (OEMs) or their authorized distributors and resellers.
F/17 Integrate C-SCRM into incident management program and processes.
Implement a robust incident management program to successfully identify, respond to, and mitigate security incidents. This program will be capable of identifying the root cause of security incidents, including those that originate from the cybersecurity supply chain.
F/18 Establish processes for suppliers and providers to disclose product vulnerabilities.
Establish internal processes to validate suppliers and service providers actively identify and disclose vulnerabilities in their products.
F/19 Establish capability for managing and monitoring components of software.
Establish a governance capability for managing and monitoring components of embedded software to manage risk across the enterprise (e.g., Software Bills of Materials [SBOMs] paired with criticality, vulnerability, threat, and exploitability to make this more automated).
Sustaining Practices Sustaining practices should be used to enhance the efficacy of C-SCRM. These practices are inclusive of and build upon foundational practices. Enterprises that have broadly standardized and implemented foundational practices should consider these as the next steps in advancing their cybersecurity supply chain risk management capabilities.
Table C-2: Sustaining Practices
# Practice S/1 Integrate C-SCRM into threat-informed security program.
Establish and collaborate with a threat-informed security program.
S/2 Use of third-party assessments, site visits, and formal certification.
Use confidence-building mechanisms, such as third-party assessment surveys, on-site visits, and formal certifications (e.g., ISO 27001) to assess critical supplier security capabilities and practices.
S/3 Establish formal supplier monitoring.
This Document Contains Controlled Unclassified Information (CUI)
# Practice Establish formal processes and intervals for continuous monitoring and reassessment of suppliers, supplied products and services, and the supply chain itself for potential changes to the risk profile.
S/4 Define C-SCRM risk appetite and tolerance levels.
Use the enterprise’s understanding of its C-SCRM risk profile (or risk profiles specific to mission and business areas) to define a risk appetite and risk tolerances to empower leaders with delegated authority across the enterprise to make C-SCRM decisions in alignment with the enterprise’s mission imperatives and strategic goals and objectives.
S/5 Establish formalized information sharing processes (e.g., with ISACs, FASC, etc.).
Use a formalized information-sharing function to engage with ISACs, the FASC, and other government agencies to enhance the enterprise’s supply chain cybersecurity threat and risk insights and help ensure a coordinated and holistic approach to addressing cybersecurity risks throughout the supply chain that may affect a broader set of agencies, the private sector, or national security.
S/6 Regularly report C-SCRM risks to executives and risk committees.
Coordinate with the enterprise’s cybersecurity program leadership to elevate top C- SCRM Risk Profile risks to the most senior enterprise risk committee.
S/7 Formal C-SCRM training program.
Embed C-SCRM-specific training into the training curriculums of applicable roles across the enterprise processes involved with C-SCRM, including information security, procurement, risk management, engineering, software development, IT, legal, and
HR.
S/8 Integrate C-SCRM into SDLC.
Integrate C-SCRM considerations into every aspect of the system and product life cycle, and implement consistent, well-documented, repeatable processes for systems engineering, cybersecurity practices, and acquisition.
S/9 Integrate C-SCRM into contractual agreements.
Integrate the enterprise’s defined C-SCRM requirements into the contractual language found in agreements with suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers.
S/10 Suppliers participate in incident response, disaster recovery, and contingency planning.
Include critical suppliers in contingency planning, incident response, and disaster recovery planning and testing.
S/11 Collaborate with suppliers to improve their cybersecurity practices.
Engage with suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers to improve their cybersecurity practices.
S/12 Formally define, collect, and report C-SCRM metrics.
Define, collect, and report C-SCRM metrics to ensure risk-aware leadership, enable active management of the completeness of C-SCRM implementations, and drive the efficacy of the enterprise’s C-SCRM processes and practices.
This Document Contains Controlled Unclassified Information (CUI)
Enhancing Practices Enhancing practices should be applied by the enterprise with the goal of advancing toward adaptive and predictive C-SCRM capabilities. Enterprises should pursue these practices once sustaining practices have been broadly implemented and standardized across the enterprise.
Table C-3: Enhancing Practices
# Practice E/1 Leverage tools for automating C-SCRM processes.
Automate C-SCRM processes where applicable and practical to drive execution consistency, efficiency, and make available the critical resources required for other critical C-SCRM activities.
E/2 Use quantitative risk analyses techniques.
Adopt quantitative risk analyses that apply probabilistic approaches (e.g., Bayesian analysis) to reduce uncertainty about the likelihood and impact of cybersecurity risks throughout the supply chain, optimize the allocation of resources to risk response, and measure return on investment (i.e., response effectiveness).
E/3 Apply predictive and adaptive C-SCRM strategies and processes.
Apply insights gained from leading C-SCRM metrics (i.e., forward-looking indicators) to shift from reactive to predictive C-SCRM strategies and plans that adapt to risk profile changes before they occur.
E/4 Establish or participate in community of practice.
Establish or participate in a community of practice (e.g., Center of Excellence) as appropriate to enhance and improve C-SCRM practices.
| 1.0 Introduction |
| 1.1 Document Purpose |
| 1.2 Authority |
| 1.3 Intended Audience |
| 1.4 Revisions and Maintenance |
| 2.0 Organizational Approach to C-SCRM |
| 2.1 Organizational Overview |
| 2.2 Key Objectives |
| 2.3 Information Systems Overview |
| 2.4 Roles and Responsibilities |
| 2.5 Assumptions |
| 2.6 Constraints |
| 2.7 Critical Success Factors |
| 2.8 Tools and Technologies |
| 3.0 C-SCRM Key Practices |
| 3.1 C-SCRM Key Practices – Level of Implementation (LOI) Self-Assessment |
| 4.0 High-Level Implementation Plans and Progress Tracking |
| Appendix A Glossary/Acronyms |
| Appendix B References and Related Publications |
| Appendix C C-SCRM Key Practices Reference |
File details come from the government source that posted it. Updated .