Mission and audience
Make supplier, product, service, software, and dependency risk visible and managed from selection through exit.
Supply-chain risk cannot be reduced by questionnaires alone. It requires ownership, criticality, due diligence, contractual requirements, technical visibility, monitoring, incident coordination, and exit planning.
Guided phase
Establish the program
Define strategy, roles, and integration with enterprise risk management.
Actions to take
- Define accountable owners and decision rights.
- Integrate supply-chain risk into architecture, risk, procurement, and change processes.
- Set consistent methods for criticality and risk acceptance.
C-SCRM Program and Strategy
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Supply Chain Roles and Responsibilities
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
Integrate C-SCRM with Risk Management
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
Guided phase
Prioritize and select suppliers
Know which suppliers matter most and perform risk-informed due diligence before commitment.
Actions to take
- Tier suppliers by mission, data, access, concentration, and recoverability.
- Assess critical suppliers before acquisition.
- Validate claims with evidence appropriate to the risk.
Prioritize Suppliers by Criticality
Suppliers are known and prioritized by criticality
Supplier Due Diligence
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
Assess Critical Suppliers Before Acquisition
Critical suppliers are assessed prior to acquisition
Guided phase
Set requirements and monitor risk
Put security obligations into agreements and monitor products, services, and third parties during the relationship.
Actions to take
- Define logging, notification, access, vulnerability, assurance, and exit requirements.
- Inventory supplier-provided services and dependencies.
- Monitor material changes, incidents, control failures, and concentration risk.
Supply Chain Requirements in Agreements
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Monitor Supplier and Third-Party Risk
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Supplier-Provided Service Inventories
Inventories of services provided by suppliers are maintained
Guided phase
Secure the lifecycle
Manage authenticity, provenance, updates, end-of-life, and post-relationship obligations.
Actions to take
- Assess hardware and software authenticity and integrity.
- Track component, update, support, and end-of-life risk.
- Plan data return, deletion, access revocation, transition, and evidence retention.
Life-Cycle Supply Chain Security
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
Post-Relationship Supply Chain Provisions
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
Assess Hardware and Software Authenticity
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
Guided phase
Coordinate incidents and improvements
Include suppliers in incident, recovery, testing, and improvement activities.
Actions to take
- Test notification and coordination paths with critical suppliers.
- Monitor external service activities and dependencies.
- Convert exercises and incidents into contractual and technical improvements.
Include Suppliers in Incident Activities
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
Monitor External Service Providers
External service provider activities and services are monitored to find potentially adverse events
Improvements from Tests and Exercises
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Completion evidence
What should exist when this playbook is working?
- Approved C-SCRM strategy, roles, and risk method.
- Critical supplier and external-service inventory with tiering rationale.
- Due-diligence and approval records.
- Security, evidence, incident, and exit clauses in agreements.
- Ongoing monitoring and material-change evidence.
- Supplier-inclusive incident and recovery exercise results.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.