Skip to main content

πŸ’Ό PM-30 Supply Chain Risk Management Strategy

  • Contextual name: πŸ’Ό PM-30 Supply Chain Risk Management Strategy
  • ID: /frameworks/nist-sp-800-53-r5/pm/30
  • Located in: πŸ’Ό PM Program Management

Description​

a. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services;

  1. Implement the supply chain risk management strategy consistently across the organization; and (a) Review and update the supply chain risk management strategy on [Assignment: organization-defined frequency] or as required, to address organizational changes.

Similar​

  • Internal
    • ID: dec-c-ab4cf434

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό DE.AE-04: The estimated impact and scope of adverse events are understood14
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.OC-02: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered7
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.OC-05: Outcomes, capabilities, and services that the organization depends on are understood and communicated4
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.OV-01: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.OV-02: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.RM-03: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.RM-04: Strategic direction that describes appropriate risk response options is established and communicated
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.RM-05: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.RM-06: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.RM-07: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.SC-01: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.SC-02: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.SC-03: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes7
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.SC-09: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.RA-06: Risk responses are chosen, prioritized, planned, tracked, and communicated7

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PM-30(1) Supply Chain Risk Management Strategy _ Suppliers of Critical or Mission-essential Items