# Cybersecurity Supply Chain Risk Management (C-SCRM)

Canonical URL: <https://www.nobledesktop.com/classes/cybersecurity-supply-chain-risk-management-c-scrm>

## Overview

A practitioner course in cybersecurity supply chain risk management, structured closely on NIST SP 800-161r1 and running the whole arc: foundations and threats, criticality analysis, integration with enterprise risk management, program building, supplier assessment, procurement requirements, controls, software supply chain, monitoring, and the full supplier lifecycle, closing in an applied workshop. Two design decisions give it real depth. Criticality is taught early, ahead of any supplier assessment, because an organization that assesses every supplier equally exhausts its budget before reaching the ones that could halt operations. And the three-level model — organization, mission and business process, and system — separates the layers practitioners most often collapse together and then cannot explain to leadership.

**Currency is the differentiator here, and it is checkable rather than promotional.** The supply chain regulatory layer has been rewritten repeatedly since early 2025, and this course is built to the baseline as of August 2026. The sharpest illustration: the secure-software attestation mandate was rescinded in January 2026 and is now optional for the organizations it once bound, so training that still teaches mandatory attestation is describing a regime that has gone. The closing module teaches participants to verify for themselves whether a cited clause, prohibition or deadline remains in force. The software supply chain material goes well past naming SBOM, working through SPDX and CycloneDX, VEX as the artifact that establishes whether a listed vulnerability is actually exploitable, build-integrity levels, and artifact-signing and project-health tooling. The NIST core is vendor-neutral and transfers directly to any third-party risk program, with the procurement-specific content kept as a marked thread rather than woven throughout.

## What you'll learn

- Define cybersecurity supply chain risk and distinguish it from traditional supply chain risk
- Identify supply chain threat sources, including counterfeit and compromised components, firmware tampering, and supplier compromise
- Perform criticality and dependency analysis, and identify single points of failure and concentration risk
- Separate organization-level, mission and business-process-level, and system-level C-SCRM, and escalate risk to the right decision-maker
- Build a C-SCRM strategy, policy set and system-level plan, and coordinate across security, acquisition, legal, procurement and operations
- Assess supplier criticality and cybersecurity practice using an evidence-based due-diligence structure
- Define security requirements before procurement, and write them into agreements including flow-down to subcontractors
- Apply the NIST SP 800-53 Supply Chain Risk Management control family, SR-1 through SR-12
- Evaluate software supply chain risk using SBOM, VEX, build-integrity levels and project-health tooling
- Assess AI and machine learning suppliers, including model and training-data provenance
- Treat cryptographic inventory and agility as a supplier due-diligence question
- Monitor supplier risk continuously, respond to supplier incidents, and manage risk through end-of-life and supplier transitions
- Verify whether a cited rule, clause or deadline is still current before relying on it

## Prerequisites

Foundational cybersecurity knowledge. Familiarity with procurement or third-party risk processes is helpful but not required.

## Curriculum

#### Module 1

- Know Your Chain: C-SCRM Foundations
- Defining C-SCRM
- Traditional versus cybersecurity supply chain risk
- Products, services, suppliers, developers, integrators and service providers
- First-party, third-party and downstream relationships
- Dependencies and inherited risk
- Why reduced visibility creates risk

#### Module 2

- Where Risk Enters: Supply Chain Threats and Vulnerabilities
- Threat sources
- Counterfeit, compromised and malicious components
- Software and firmware tampering
- Vulnerable or malicious third-party software
- Supplier and service-provider compromise
- Insider risk within the supply chain
- Supplier disruption and loss of availability

#### Module 3

- See What Matters: Criticality and Dependency Analysis
- Identifying critical systems, components, data and services
- Mission and business dependencies
- Critical suppliers
- Single points of failure
- Concentration and systemic risk
- Upstream and downstream dependencies
- Prioritizing resources by criticality

#### Module 4

- Three Levels, One Risk Picture: Integrating C-SCRM into Risk Management
- C-SCRM within enterprise risk management
- Organization, mission and business-process, and system levels
- Risk appetite and tolerance
- Roles across levels
- Escalation to decision-makers
- Connecting to the Risk Management Framework and to supply chain's place in the Govern function of Cybersecurity Framework 2.0

#### Module 5

- Build the Program: C-SCRM Strategy, Policy, and Planning
- Developing a strategy
- Policies and procedures
- Implementation planning
- System-level C-SCRM plans
- Governance and accountability
- Coordinating cybersecurity, acquisition, legal, procurement and operations
- Measuring and improving capability

#### Module 6

- Know Your Supplier: Supplier Risk Assessment
- Identifying and categorizing suppliers
- Determining criticality
- Evaluating supplier cybersecurity practice
- Assessing products and services before acquisition
- Sources of supplier risk information
- Evidence-based assessment across foreign ownership control or influence, provenance, resilience, foundational cyber practices and supply chain tiers
- Risk scoring
- When additional assurance is required

#### Module 7

- Security Before the Signature: Acquisition and Supplier Requirements
- Integrating cybersecurity into acquisition
- Defining and communicating security requirements before procurement
- Requirements in agreements and contracts
- Flow-down to subcontractors
- Supplier notification and incident-reporting expectations
- Vulnerability disclosure and remediation
- Authenticity, provenance and integrity
- Acquisition strategies that reduce exposure

#### Module 8

- Trust but Verify: Supply Chain Controls and Assurance
- The SP 800-53 Supply Chain Risk Management control family
- SR-1 through SR-12
- Supply chain risk management plans
- Supplier assessments and reviews
- Tamper resistance and detection
- Component authenticity
- Supplier notification agreements
- Inspection of systems and components
- Component disposal
- Selecting controls by organizational risk

#### Module 9

- Software in the Chain: Software Supply Chain Risk
- Software as a dependency
- Commercial, open-source and internally developed software
- Third-party libraries
- Provenance and integrity
- SBOM formats including SPDX and CycloneDX
- VEX and exploitability context
- Build-integrity levels
- Project-health and artifact-signing tooling
- Patch integrity
- Risks in build and development environments

#### Module 10

- Stay Ahead of the Chain: Monitoring and Response
- Continuous monitoring of suppliers
- Tracking changes in supplier risk
- Vulnerability and threat intelligence
- Supplier security incidents
- Supply chain incident response
- Reassessment triggers
- Changes in ownership, products or services
- Risk acceptance, mitigation, transfer, avoidance and sharing
- Updating the risk register

#### Module 11

- From Supplier to Sunset: Lifecycle C-SCRM
- C-SCRM across the system development lifecycle
- Planning and acquisition
- Development and integration
- Operations and maintenance
- Supplier changes and replacement
- End-of-life and end-of-support risk
- Secure component disposal
- Data and credential protection during supplier transitions

#### Module 12

- Put It Together: C-SCRM Scenario Workshop
- Identify assets, suppliers and dependencies in a sample environment, determine which are most critical, build threat scenarios, assess likelihood and impact, evaluate supplier evidence, select risk responses and controls, draft supplier security requirements, document a risk register and justify a C-SCRM decision

#### Module 13

- The Ground Is Moving: Regulatory Currency and Emerging Domains
- AI and machine learning supply chain risk including model and training-data provenance, malicious models in public repositories, and vendor-disclosure obligations for procured AI
- Post-quantum cryptography as a supply chain domain, cryptographic inventory and agility as due-diligence questions, and the 2030 federal compliance deadline
- And how to verify whether a federal clause, prohibition or deadline is still in force

## Schedule
- Jan 22, 2027 – Jan 25, 2027 — Live Online
- Feb 16, 2027 – Feb 17, 2027 — Live Online
- Mar 8, 2027 – Mar 9, 2027 — Live Online
- Apr 22, 2027 – Apr 23, 2027 — Live Online
- May 17, 2027 – May 18, 2027 — Live Online
- Jun 8, 2027 – Jun 9, 2027 — Live Online
- Jul 22, 2027 – Jul 23, 2027 — Live Online

## Pricing

**Tuition:** $1049
