Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Supply Chain Risk

Establish a cybersecurity supply-chain program, prioritize suppliers, set agreement requirements, monitor risk across the lifecycle, and integrate suppliers into incident and recovery work.

5Guided phases
15CSF outcomes
61Mapped controls
21D3FEND techniques

Third-party risk playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Make supplier, product, service, software, and dependency risk visible and managed from selection through exit.

Supply-chain risk cannot be reduced by questionnaires alone. It requires ownership, criticality, due diligence, contractual requirements, technical visibility, monitoring, incident coordination, and exit planning.

Built forProcurement · Third-party risk teams · Security architects · Legal teams · Service owners
01

Guided phase

Establish the program

Define strategy, roles, and integration with enterprise risk management.

Actions to take

  • Define accountable owners and decision rights.
  • Integrate supply-chain risk into architecture, risk, procurement, and change processes.
  • Set consistent methods for criticality and risk acceptance.
GV.SC-01Govern · Cybersecurity Supply Chain Risk Management

C-SCRM Program and Strategy

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

3 controls2 800-171
GV.SC-02Govern · Cybersecurity Supply Chain Risk Management

Supply Chain Roles and Responsibilities

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally

3 controls3 800-171
GV.SC-03Govern · Cybersecurity Supply Chain Risk Management

Integrate C-SCRM with Risk Management

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

28 controls5 800-1712 800-1727 D3FEND4 mitigations
02

Guided phase

Prioritize and select suppliers

Know which suppliers matter most and perform risk-informed due diligence before commitment.

Actions to take

  • Tier suppliers by mission, data, access, concentration, and recoverability.
  • Assess critical suppliers before acquisition.
  • Validate claims with evidence appropriate to the risk.
GV.SC-06Govern · Cybersecurity Supply Chain Risk Management

Supplier Due Diligence

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

4 controls3 800-171
03

Guided phase

Set requirements and monitor risk

Put security obligations into agreements and monitor products, services, and third parties during the relationship.

Actions to take

  • Define logging, notification, access, vulnerability, assurance, and exit requirements.
  • Inventory supplier-provided services and dependencies.
  • Monitor material changes, incidents, control failures, and concentration risk.
GV.SC-05Govern · Cybersecurity Supply Chain Risk Management

Supply Chain Requirements in Agreements

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

6 controls4 800-1711 800-172
GV.SC-07Govern · Cybersecurity Supply Chain Risk Management

Monitor Supplier and Third-Party Risk

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

5 controls3 800-1711 800-172
04

Guided phase

Secure the lifecycle

Manage authenticity, provenance, updates, end-of-life, and post-relationship obligations.

Actions to take

  • Assess hardware and software authenticity and integrity.
  • Track component, update, support, and end-of-life risk.
  • Plan data return, deletion, access revocation, transition, and evidence retention.
GV.SC-09Govern · Cybersecurity Supply Chain Risk Management

Life-Cycle Supply Chain Security

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

13 controls6 800-1712 800-1727 D3FEND4 mitigations
GV.SC-10Govern · Cybersecurity Supply Chain Risk Management

Post-Relationship Supply Chain Provisions

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

10 controls7 800-1713 800-17212 D3FEND10 mitigations
ID.RA-09Identify · Risk Assessment

Assess Hardware and Software Authenticity

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

11 controls2 800-1718 800-1723 D3FEND2 mitigations
05

Guided phase

Coordinate incidents and improvements

Include suppliers in incident, recovery, testing, and improvement activities.

Actions to take

  • Test notification and coordination paths with critical suppliers.
  • Monitor external service activities and dependencies.
  • Convert exercises and incidents into contractual and technical improvements.
GV.SC-08Govern · Cybersecurity Supply Chain Risk Management

Include Suppliers in Incident Activities

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

7 controls4 800-1711 800-172
DE.CM-06Detect · Continuous Monitoring

Monitor External Service Providers

External service provider activities and services are monitored to find potentially adverse events

5 controls3 800-1715 800-1722 D3FEND3 mitigations
ID.IM-02Identify · Improvement

Improvements from Tests and Exercises

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

40 controls15 800-17113 800-17221 D3FEND17 mitigations

Completion evidence

What should exist when this playbook is working?

  • Approved C-SCRM strategy, roles, and risk method.
  • Critical supplier and external-service inventory with tiering rationale.
  • Due-diligence and approval records.
  • Security, evidence, incident, and exit clauses in agreements.
  • Ongoing monitoring and material-change evidence.
  • Supplier-inclusive incident and recovery exercise results.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.