13.04.2015 Views

NIST.SP.800-161

NIST.SP.800-161

NIST.SP.800-161

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Special Publication 800-<strong>161</strong><br />

Supply Chain Risk Management Practices for Federal<br />

Information Systems and Organizations<br />

________________________________________________________________________________________________________<br />

program/project or individual information system needs, are defined in this step. The data and information<br />

collected during Frame provides inputs for scoping and fine-tuning ICT SCRM activities in other risk<br />

management process steps throughout the three tiers.<br />

[<strong>NIST</strong> SP 800-39] defines risk framing as “the set of assumptions, constraints, risk tolerances, and<br />

priorities/trade-offs that shape an organization’s approach for managing risk.” ICT SCRM risk framing<br />

should be integrated into the overall organization risk framing process. Outputs of the organization’s risk<br />

framing and the overall risk management process should serve as inputs into the ICT SCRM risk framing,<br />

including but not limited to:<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

Organization policies, strategies, and governance;<br />

Applicable laws and regulations;<br />

Mission functions and business goals;<br />

Organization processes (security, quality, etc.);<br />

Organization threats, vulnerabilities, risks, and risk tolerance;<br />

Criticality of mission functions;<br />

Enterprise architecture;<br />

Mission-level security policies;<br />

Functional requirements; and<br />

Security requirements.<br />

ICT SCRM risk framing is an iterative process that also uses inputs from the other steps of the risk<br />

management process (Assess, Respond, and Monitor) as inputs. Figure 2-5 depicts the Frame Step with<br />

its inputs and outputs along the three organizational tiers.<br />

CHAPTER 2 PAGE 24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!