本文分析了美国联邦信息系统和组织的供应链风险管理实践指导草案,并从ICT供应链风险管理的目标、应用范围、制定背景、实践和标准形成五个方面探讨了NIST SP 800-161的主要内容。最后提出了ICT供应链风险管理标准在新背景下需完善的几个方面。
We analyze the draft of Supply Chain Risk Management Practices for Federal Information Systems and Organizations. Then, we discuss the content of NIST SP800-161 in five aspects: purpose, scope, background, foundational practice and standard formation of ICT SCRM. Finally, we purpose the several aspects need to be improved in ICT SCRM standards.
China Standards Review