Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Noble Desktop

Cybersecurity Supply Chain Risk Management (C-SCRM)

via Noble Desktop

Overview

Most organizations cannot see past their direct suppliers, and that is exactly where the risk sits. Learn to find what actually matters in a supply chain, write real security requirements into agreements before signing, and verify that suppliers did what they claimed.

Syllabus

Module 1

  • Know Your Chain: C-SCRM Foundations
  • Defining C-SCRM
  • Traditional versus cybersecurity supply chain risk
  • Products, services, suppliers, developers, integrators and service providers
  • First-party, third-party and downstream relationships
  • Dependencies and inherited risk
  • Why reduced visibility creates risk

Module 2

  • Where Risk Enters: Supply Chain Threats and Vulnerabilities
  • Threat sources
  • Counterfeit, compromised and malicious components
  • Software and firmware tampering
  • Vulnerable or malicious third-party software
  • Supplier and service-provider compromise
  • Insider risk within the supply chain
  • Supplier disruption and loss of availability

Module 3

  • See What Matters: Criticality and Dependency Analysis
  • Identifying critical systems, components, data and services
  • Mission and business dependencies
  • Critical suppliers
  • Single points of failure
  • Concentration and systemic risk
  • Upstream and downstream dependencies
  • Prioritizing resources by criticality

Module 4

  • Three Levels, One Risk Picture: Integrating C-SCRM into Risk Management
  • C-SCRM within enterprise risk management
  • Organization, mission and business-process, and system levels
  • Risk appetite and tolerance
  • Roles across levels
  • Escalation to decision-makers
  • Connecting to the Risk Management Framework and to supply chain's place in the Govern function of Cybersecurity Framework 2.0

Module 5

  • Build the Program: C-SCRM Strategy, Policy, and Planning
  • Developing a strategy
  • Policies and procedures
  • Implementation planning
  • System-level C-SCRM plans
  • Governance and accountability
  • Coordinating cybersecurity, acquisition, legal, procurement and operations
  • Measuring and improving capability

Module 6

  • Know Your Supplier: Supplier Risk Assessment
  • Identifying and categorizing suppliers
  • Determining criticality
  • Evaluating supplier cybersecurity practice
  • Assessing products and services before acquisition
  • Sources of supplier risk information
  • Evidence-based assessment across foreign ownership control or influence, provenance, resilience, foundational cyber practices and supply chain tiers
  • Risk scoring
  • When additional assurance is required

Module 7

  • Security Before the Signature: Acquisition and Supplier Requirements
  • Integrating cybersecurity into acquisition
  • Defining and communicating security requirements before procurement
  • Requirements in agreements and contracts
  • Flow-down to subcontractors
  • Supplier notification and incident-reporting expectations
  • Vulnerability disclosure and remediation
  • Authenticity, provenance and integrity
  • Acquisition strategies that reduce exposure

Reviews

Start your review of Cybersecurity Supply Chain Risk Management (C-SCRM)

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.