NIST has just released the second public draft of Special Publication (SP) 800-161 Revision 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, for public comment. We listened to your comments from earlier this year about the first version, we’ve made new changes, and we are hoping to get your feedback again on our new draft.
The initial public draft was published in April of 2021 and preceded the release of the President’s Executive Order (EO) on “Improving the Nation’s Cybersecurity (14028)” issued on May 12, 2021. This EO charged multiple agencies—including NIST—with enhancing cybersecurity through a variety of initiatives, but with a specific focus on the security and integrity of the software supply chain.
What is different about this second version?
We worked on making the implementation guidance more consumable by different audiences by revising the structure of the document and adding Audience Profiles. We also added two NEW appendices focused more specifically on Federal departments and agencies:
How are comments submitted?
Comments are due by December 10, 2021. December 3, 2021. The template for comment submissions, along with instructions and more information, can be found on our website. As always, we are thankful for your support; your ideas will continue to help shape our final publication to ensure it meets the needs and expectations of our customers. We plan to release a final draft of NIST SP 800-161 Revision 1 during the third quarter of 2022.
Security and Privacy: cybersecurity supply chain risk management