TPRM Cyber Frameworks Flashcards
TPRM Cyber Frameworks
Just as in Cyber, there are a few available frameworks to guide how to implement and run third-party risk assessments from a cybersecurity perspective. This course will focus on two ‘biggest’ available:
-NIST 800-161 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
-ISO 27036-1:2021 - Cybersecurity Supplier relationships
https://www.iso.org/standard/82905.html
*A TPRM framework does not current exist; however, the TPRA is working with the community to develop one.
**Need to know these frameworks exist! Do not need to know the ins and outs!
NIST 800-161
Great way if you’re looking for a way your organization should be aligned for cybersecurity, great place to start. Looking at the cyber supply chain