# Cybersecurity Supply Chain Risk Management (C-SCRM) (Self-Paced)

Canonical URL: <https://www.nobledesktop.com/classes/cybersecurity-supply-chain-risk-management-c-scrm-self-paced>

## Overview

A complete self-paced treatment of cybersecurity supply chain risk management, following the structure of NIST SP 800-161r1 closely. The route runs from foundations and threat sources through criticality analysis, folding C-SCRM into enterprise risk management, standing up the program, assessing suppliers, setting procurement requirements, applying controls, handling the software supply chain, monitoring, and managing the supplier relationship to its end — finishing in an applied workshop. Two deliberate choices give the course more depth than its length suggests. Criticality analysis comes before any supplier assessment, because treating every supplier as equally important burns the budget long before you reach the handful that could halt operations. And the three-level model keeps organization, mission and business process, and system-level C-SCRM distinct — the exact distinction practitioners tend to blur, and then cannot untangle in front of leadership.

**What sets this course apart is that its currency is checkable, not a marketing claim.** Supply chain regulation has been rewritten again and again since early 2025, and the material here reflects the position as of August 2026. Take the clearest case: the secure-software attestation mandate was rescinded in January 2026 and is now left to each organization to decide, so any course still presenting attestation as compulsory is teaching a regime that has already ended. The last module therefore teaches the skill itself — how to establish for yourself whether a clause, prohibition or deadline is still in force. On software, the course goes well beyond defining SBOM: SPDX and CycloneDX formats, VEX as the artifact that tells you whether a listed vulnerability is genuinely exploitable, build-integrity levels, and tooling for artifact signing and project health. The NIST core is vendor-neutral and drops straight into any third-party risk program, with the procurement-specific content running as a clearly marked thread instead of being spread through everything.

## What you'll learn

- Define cybersecurity supply chain risk and distinguish it from traditional supply chain risk
- Identify supply chain threat sources, including counterfeit and compromised components, firmware tampering, and supplier compromise
- Perform criticality and dependency analysis, and identify single points of failure and concentration risk
- Separate organization-level, mission and business-process-level, and system-level C-SCRM, and escalate risk to the right decision-maker
- Build a C-SCRM strategy, policy set and system-level plan, and coordinate across security, acquisition, legal, procurement and operations
- Assess supplier criticality and cybersecurity practice using an evidence-based due-diligence structure
- Define security requirements before procurement, and write them into agreements including flow-down to subcontractors
- Apply the NIST SP 800-53 Supply Chain Risk Management control family, SR-1 through SR-12
- Evaluate software supply chain risk using SBOM, VEX, build-integrity levels and project-health tooling
- Assess AI and machine learning suppliers, including model and training-data provenance
- Treat cryptographic inventory and agility as a supplier due-diligence question
- Monitor supplier risk continuously, respond to supplier incidents, and manage risk through end-of-life and supplier transitions
- Verify whether a cited rule, clause or deadline is still current before relying on it

## Prerequisites

Foundational cybersecurity knowledge. Familiarity with procurement or third-party risk processes is helpful but not required.

## Pricing

**Tuition:** $1049
