3NIST. Notional Supply Chain Risk Management Practices for Federal Information Systems[M]. Gaithersburg: NIST, 2012.
4ISO/IEC. ISO/IEC WD 27036-3. Information technology--Security techniques--Information security for supplier relationships Part 3: Guidelines for ICT supply chain[S]. ISO/IEC, 2011.