# What is Supply-Chain Security?

> Supply-chain security is the protection of products, services, components, data, and delivery relationships against compromise, substitution, disruption, or unacceptable dependency risk throughout their lifecycle.

- Canonical URL: https://yellowcube.eu/glossary/supply-chain-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

In cybersecurity, the scope can include hardware, firmware, software, cloud and managed services, development and build systems, distributors, maintainers, update channels, and upstream suppliers.

Cybersecurity supply chain risk management (C-SCRM) is the discipline commonly used to govern these risks; it is not merely vendor rating. Organizations need confidence in what they acquire, how it was produced and delivered, which dependencies it introduces, how vulnerabilities and incidents will be handled, and whether critical capabilities can continue or be replaced. Suppliers also need controls for their own dependencies and deliverables.

### Key points

- **Understand the chain:** Map critical products and services, component and supplier dependencies, privileged connections, data flows, geographic or ownership concerns, and single points of failure.
- **Build security in:** Use secure development and engineering practices, protected build and signing systems, component provenance, change control, tamper detection, and vulnerability disclosure and remediation processes.
- **Govern acquisition:** Set risk-based requirements, evaluate relevant evidence, define responsibilities contractually, control approved sources, and reassess major changes and subcontractors.
- **Design for disruption:** Maintain alternatives, protected recovery materials, exit plans, and tested procedures for a supplier outage, compromise, unsafe update, or loss of support.
- **Important limitation:** An SBOM, supplier attestation, certification, country-of-origin check, or one-time assessment addresses only part of supply-chain risk. None proves that a product is secure or that a dependency will remain available.

### Related terms

[Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Software bill of materials (SBOM)](<https://yellowcube.eu/glossary/software-bill-of-materials/>) · [Secure by design](<https://yellowcube.eu/glossary/secure-by-design/>) · [Business continuity](<https://yellowcube.eu/glossary/business-continuity/>) · [Cyber Resilience Act (CRA)](<https://yellowcube.eu/glossary/cyber-resilience-act/>)

### Sources

[NIST SP 800-161 Rev. 1 Update 1: Cybersecurity Supply Chain Risk Management](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final) · [NIST Cybersecurity Framework 2.0](https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final) · [CISA ICT Supply Chain Risk Management](https://www.cisa.gov/sites/default/files/publications/factsheet_ict-scrm_508.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

