Draft NIST Guidance Highlights Supply Chain Fundamentals as Key Practices in Cyber Supply Chain Risk Management
Client Alert | 1 min read | 02.21.20
Last week, the National Institute of Standards and Technology (NIST) published the draft NISTIR 8276 “Key Practices in Cyber Supply Chain Risk Management” providing Key Practices and related recommendations for monitoring, controlling, and understanding how to conduct cyber – supply chain risk management (C-SCRM). The Eight Key Practices are general and apply equally, in practice, to both traditional supply chain management and C-SCRM, including:
- Integrating SCRM across the organization,
- Understanding the organization’s supply chain, and
- Assessing and monitoring SCRM throughout the supplier relationship.
Specific guidance includes, among others:
- Increasing Board involvement in C-SCRM;
- Understanding the cyber relationship with suppliers, including whether they process critical data; and
- Using third-party assessments to evaluate suppliers.
The guidance should serve to remind organizations of the need to know their supply chain well and to have a purposeful approach to its management. Organizations have an opportunity to comment on this draft guidance until March 4, 2020.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 09.10.26
European Commission Publishes Landmark Guidelines on Exclusionary Abuses by Dominant Companies
On 3 September 2026, the European Commission adopted new Guidelines on the application of Article 102 TFEU to abusive exclusionary conduct by dominant undertakings. The Guidelines follow a public consultation on a draft published in August 2024 and reflect substantial stakeholder feedback. They replace the Commission's 2008 Guidance on enforcement priorities (which ceases to apply 30 days after publication of the new guidelines in the Official Journal) and represent the most significant reset of the Commission's Article 102 enforcement framework in nearly two decades. The Commission's stated aim is to set out principles and operational guidance, enhance legal certainty, and help companies self-assess their exclusionary-abuse risk.
Client Alert | 5 min read | 09.09.26
Client Alert | 8 min read | 09.08.26
Saxon Woods Investments Limited v Costa [2026] UKSC 21: Good Faith in the Boardroom
Client Alert | 2 min read | 09.08.26
IRS Takes Aim: Proposed Rule Threatens Tax-Exempt Status of Private Schools

