United States

NIST SP 800-161

34 controls. 1 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

34 controls 1 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-161 Cybersecurity Supply Chain Risk Management Evidence & Implementation Kit

34 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

If you runShared controls
NIST SP 800-53 Rev 515measure it →

Every control

CodeControlAlso in
SCRM-ACQ-1Acquisition Process Integration0
SCRM-ACQ-2Supplier Security Requirements0
SCRM-ACQ-3Flow-Down to Sub-Tier Suppliers0
SCRM-COMP-1Component Authenticity0
SCRM-COMP-2Software Bill of Materials Use0
SCRM-COMP-3Provenance and Pedigree Tracking0
SCRM-GOV-1C-SCRM Governance Structure0
SCRM-GOV-2C-SCRM Policy Framework0
SCRM-GOV-3C-SCRM Strategy and Implementation Plan0
SCRM-INC-1Supply Chain Incident Response0
SCRM-INC-2Vulnerability Disclosure and Response in Supply Chain0
SCRM-MEAS-1C-SCRM Metrics and Reporting0
SCRM-RES-1Supply Chain Resilience and Continuity0
SCRM-RES-2Supply Chain Information Sharing0
SCRM-RM-1Supply Chain Risk Assessment0
SCRM-RM-2Criticality Analysis0
SCRM-SUP-1Supplier Due Diligence0
SCRM-SUP-2Continuous Supplier Monitoring0
SCRM-SUP-3Supplier Performance and Issue Management0
SP800-161-ASSESSRisk Process: Assess1
SP800-161-CONTROLS-ACICT SCRM Control Family: Access Control1
SP800-161-CONTROLS-SAICT SCRM Control Family: System and Services Acquisition1
SP800-161-CONTROLS-SRICT SCRM Control Family: Supply Chain Risk Management1
SP800-161-CRITICALITYCriticality Analysis1
SP800-161-FOUND-PRACTICESFoundational ICT SCRM Practices1
SP800-161-FRAMERisk Process: Frame1
SP800-161-INCIDENTSupply Chain Incident Management1
SP800-161-MONITORRisk Process: Monitor1
SP800-161-PROVENANCEProvenance and Traceability1
SP800-161-RESPONDRisk Process: Respond1
SP800-161-SUPPLIERSupplier Relationship Management1
SP800-161-TIER1Multitiered Risk: Tier 1 (Organization)1
SP800-161-TIER2Multitiered Risk: Tier 2 (Mission/Business Process)1
SP800-161-TIER3Multitiered Risk: Tier 3 (Information Systems)1

Tell me when NIST SP 800-161 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • security charter
  • board reporting pack
  • risk register
  • policy library
  • Executive sponsor designation
  • PDPA compliance roadmap
  • Annual review records
  • Approval record
  • KB articles
  • Documentation standards

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-161, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition