NIST SP 800-161R1
Definition
The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022). The primary US government guidance document for C-SCRM, providing a tiered set of practices aligned with the NIST Cybersecurity Framework.
- Title
- Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
- Revision
- Revision 1, 2022
- Publisher
- NIST
- Alignment
- NIST Cybersecurity Framework
Common questions
What does 'tiered set of practices' mean in this publication?+
The guidance scales its recommended controls to an organisation's risk profile and resources, so a small organisation and a large critical-infrastructure operator are not held to an identical checklist, but are expected to apply C-SCRM practices proportionate to their tier.
How does this standard relate to a software supply-chain compromise investigation?+
An investigator or auditor can use its practices as a benchmark to assess whether an organisation's vendor vetting, component tracking, and dependency management met recognised due-diligence expectations before or after a supply-chain incident.
Is compliance with SP 800-161r1 legally mandatory?+
It is guidance rather than law for most organisations, though specific US federal contracting or regulatory requirements may reference it, making compliance mandatory in those specific contractual or regulatory contexts rather than universally.
Related terms
- Dependency Confusion
- An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
- Software Bill of Materials (SBOM)
- A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard...
- Software Composition Analysis (SCA)
- A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
- Transitive Dependency
- A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive...
- Vendor Due Diligence
- The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due...