Supply Chain Cybersecurity

  1. Frameworks, Standards, and Compliance
    1. National and International Frameworks
      1. NIST Cybersecurity Framework
        1. Framework Core Functions
          1. Identify
            1. Protect
              1. Detect
                1. Respond
                  1. Recover
                  2. Implementation Tiers
                    1. Framework Profiles
                      1. Supply Chain Extensions
                      2. NIST Secure Software Development Framework (SSDF)
                        1. Secure Development Practices
                          1. Implementation Guidance
                            1. Measurement and Assessment
                            2. NIST SP 800-161 Supply Chain Risk Management
                              1. SCRM Controls Catalog
                                1. Implementation Guidance
                                  1. Assessment Procedures
                                  2. ISO/IEC 27036 Series
                                    1. Supplier Relationship Security
                                      1. Contractual Requirements
                                        1. Monitoring and Review
                                        2. ENISA Supply Chain Security Guidelines
                                          1. European Perspective
                                            1. Best Practice Recommendations
                                              1. Implementation Roadmaps
                                            2. Industry-Specific Standards
                                              1. Automotive Industry Standards
                                                1. ISO/SAE 21434
                                                  1. UNECE WP.29 Regulations
                                                  2. Healthcare Standards
                                                    1. HIPAA Security Requirements
                                                      1. FDA Cybersecurity Guidance
                                                      2. Financial Services Standards
                                                        1. PCI DSS Requirements
                                                          1. SWIFT Customer Security Programme
                                                          2. Telecommunications Standards
                                                            1. NESAS Framework
                                                              1. 3GPP Security Specifications
                                                            2. Regulatory Requirements
                                                              1. United States Regulations
                                                                1. Executive Order 14028
                                                                  1. CISA Binding Operational Directives
                                                                    1. FTC Act Section 5
                                                                      1. State Privacy Laws
                                                                      2. European Union Regulations
                                                                        1. Cyber Resilience Act
                                                                          1. NIS2 Directive
                                                                            1. GDPR Supply Chain Requirements
                                                                            2. Defense and Government Requirements
                                                                              1. DFARS Cybersecurity Requirements
                                                                                1. CMMC Framework
                                                                                  1. FedRAMP Authorization
                                                                                  2. International Trade Regulations
                                                                                    1. Export Administration Regulations (EAR)
                                                                                      1. International Traffic in Arms Regulations (ITAR)
                                                                                    2. Certification and Attestation Programs
                                                                                      1. Third-Party Assessments
                                                                                        1. SOC 1 Reports
                                                                                          1. SOC 2 Type I and Type II
                                                                                            1. SOC 3 Reports
                                                                                            2. Information Security Certifications
                                                                                              1. ISO/IEC 27001 Certification
                                                                                                1. Common Criteria Evaluation
                                                                                                  1. FIPS 140-2 Validation
                                                                                                  2. Cloud Security Certifications
                                                                                                    1. FedRAMP Authorization
                                                                                                      1. CSA STAR Certification
                                                                                                        1. Cloud Security Alliance (CSA) Attestations
                                                                                                        2. Industry-Specific Certifications
                                                                                                          1. Automotive SPICE
                                                                                                            1. DO-178C for Aviation
                                                                                                              1. IEC 62304 for Medical Devices