1. Home
  2. |Insights
  3. |Draft NIST Guidance Highlights Supply Chain Fundamentals as Key Practices in Cyber Supply Chain Risk Management

Draft NIST Guidance Highlights Supply Chain Fundamentals as Key Practices in Cyber Supply Chain Risk Management

Client Alert | 1 min read | 02.21.20

Last week, the National Institute of Standards and Technology (NIST) published the draft NISTIR 8276 “Key Practices in Cyber Supply Chain Risk Management” providing Key Practices and related recommendations for monitoring, controlling, and understanding how to conduct cyber – supply chain risk management (C-SCRM). The Eight Key Practices are general and apply equally, in practice, to both traditional supply chain management and C-SCRM, including:

  • Integrating SCRM across the organization,
  • Understanding the organization’s supply chain, and
  • Assessing and monitoring SCRM throughout the supplier relationship. 

Specific guidance includes, among others:

  • Increasing Board involvement in C-SCRM;
  • Understanding the cyber relationship with suppliers, including whether they process critical data; and
  • Using third-party assessments to evaluate suppliers.

The guidance should serve to remind organizations of the need to know their supply chain well and to have a purposeful approach to its management. Organizations have an opportunity to comment on this draft guidance until March 4, 2020.

Contacts

Insights

Client Alert | 5 min read | 06.05.26

Grants Overhauled: What the Proposed Rewrite of 2 CFR Part 200 Means for Federal Financial Assistance Award Recipients

The Office of Management and Budget issued on May 29, 2026 a Proposed Rule that would significantly revise the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) at 2 C.F.R. Part 200, potentially impacting the full lifecycle of federal grants, cooperative agreements and other forms of financial assistance, from pre-award merit review through post-award administration and termination. These proposed changes are designed to implement the President’s policy priorities, executive actions related to diversity, equity and inclusion (DEI) activities, and Executive Order No. 14332, Improving Oversight of Federal Grantmaking (EO 14332)....