Supply-chain risk work considers the organisations, products, services and dependencies that support your operations. Cybersecurity supply-chain risk management focuses on the security risks arising within those relationships and their life cycles.

This section introduces C-SCRM and relevant publications. Use it to frame supplier assessment, procurement decisions, ongoing assurance, incident coordination and exit planning according to the importance of the relationship.