Most organizations cannot see past their direct suppliers, and that is exactly where the risk sits. Learn to find what actually matters in a supply chain, write real security requirements into agreements before signing, and verify that suppliers did what they claimed.
Overview
Syllabus
Module 1
- Know Your Chain: C-SCRM Foundations
- Defining C-SCRM
- Traditional versus cybersecurity supply chain risk
- Products, services, suppliers, developers, integrators and service providers
- First-party, third-party and downstream relationships
- Dependencies and inherited risk
- Why reduced visibility creates risk
Module 2
- Where Risk Enters: Supply Chain Threats and Vulnerabilities
- Threat sources
- Counterfeit, compromised and malicious components
- Software and firmware tampering
- Vulnerable or malicious third-party software
- Supplier and service-provider compromise
- Insider risk within the supply chain
- Supplier disruption and loss of availability
Module 3
- See What Matters: Criticality and Dependency Analysis
- Identifying critical systems, components, data and services
- Mission and business dependencies
- Critical suppliers
- Single points of failure
- Concentration and systemic risk
- Upstream and downstream dependencies
- Prioritizing resources by criticality
Module 4
- Three Levels, One Risk Picture: Integrating C-SCRM into Risk Management
- C-SCRM within enterprise risk management
- Organization, mission and business-process, and system levels
- Risk appetite and tolerance
- Roles across levels
- Escalation to decision-makers
- Connecting to the Risk Management Framework and to supply chain's place in the Govern function of Cybersecurity Framework 2.0
Module 5
- Build the Program: C-SCRM Strategy, Policy, and Planning
- Developing a strategy
- Policies and procedures
- Implementation planning
- System-level C-SCRM plans
- Governance and accountability
- Coordinating cybersecurity, acquisition, legal, procurement and operations
- Measuring and improving capability
Module 6
- Know Your Supplier: Supplier Risk Assessment
- Identifying and categorizing suppliers
- Determining criticality
- Evaluating supplier cybersecurity practice
- Assessing products and services before acquisition
- Sources of supplier risk information
- Evidence-based assessment across foreign ownership control or influence, provenance, resilience, foundational cyber practices and supply chain tiers
- Risk scoring
- When additional assurance is required
Module 7
- Security Before the Signature: Acquisition and Supplier Requirements
- Integrating cybersecurity into acquisition
- Defining and communicating security requirements before procurement
- Requirements in agreements and contracts
- Flow-down to subcontractors
- Supplier notification and incident-reporting expectations
- Vulnerability disclosure and remediation
- Authenticity, provenance and integrity
- Acquisition strategies that reduce exposure