1、 https:/crsreports.congress.gov Updated March 21, 2022Cyber Supply Chain Risk Management: An IntroductionIntroduction A supply chain consists of the system of organizations, people, activities, information, and resources that provide products or services to consumers. Like other types of goods, a gl
2、obal supply chain exists for the development, manufacture, and distribution of information technology (IT) products (i.e., hardware and software) and information communications technology (ICT). As with other goods and services, risks exist to this cyber supply chain. This field is known as cyber su
3、pply chain risk management (C-SCRM or Cyber SCRM). Congress and federal agencies have taken actions to bolster cyber supply chain security. In 2017, the U.S. Department of Homeland Security (DHS) ordered federal agencies to remove Kaspersky security products from their networks because of the risk p
4、osed. Legislation was subsequently enacted codifying that order. In addition, Congress in 2018 instructed federal agencies and contractors not to use ICT made by certain Chinese companies. Congress established the Federal Acquisition Security Council (FASC), which issued an initial rule in 2020. The