The template for comment submissions, along with instructions and more information, can be found on our website.
FINAL DRAFT 10 RADIO TEMPLATE SOFTWARE
APPENDIX F: A Response to Executive Order 14028’s Call to Publish Preliminary Guidelines or Enhancing Software Supply Chain Security appendix, which seeks to provide a response to the directives outlined within Section 4(c) of the EO by outlining existing industry standards, tools, and recommended practices within the context of SP 800-161 Revision 1, as well as any new standards, tools, and recommended practices stemming from the EO and recent developments in the discipline.Ĭomments are due by December 10, 2021.APPENDIX E: A Federal Acquisition Supply Chain Security Act of 2018 (FASCSA) appendix, which provides additional guidance tailored to federal executive agencies related to supply chain risk assessment factors, assessment documentation, risk severity levels, and risk response.We also added two NEW appendices focused more specifically on Federal departments and agencies:
We worked on making the implementation guidance more consumable by different audiences by revising the structure of the document and adding Audience Profiles. What is different about this second version? This EO charged multiple agencies-including NIST-with enhancing cybersecurity through a variety of initiatives, but with a specific focus on the security and integrity of the software supply chain. The initial public draft was published in April of 2021 and preceded the release of the President’s Executive Order (EO) on “ Improving the Nation’s Cybersecurity (14028)” issued on May 12, 2021.
We listened to your comments from earlier this year about the first version, we’ve made new changes, and we are hoping to get your feedback again on our new draft. NIST has just released the second public draft of Special Publication (SP) 800-161 Revision 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, for public comment. 12/1/21: The comment period has been extended to December 10, 2021.