Back to Frameworks

NIST SP 800-161

United States
vRev 1
14 domains
34 controls

Cybersecurity Supply Chain Risk Management Practices

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (14)

Acquisition and Procurement

3 controls
Controls in the Acquisition and Procurement domain of NIST SP 800-1613 controls
CodeTitle
SCRM-ACQ-1Acquisition Process Integration
SCRM-ACQ-2Supplier Security Requirements
SCRM-ACQ-3Flow-Down to Sub-Tier Suppliers

Components and Services

3 controls
Controls in the Components and Services domain of NIST SP 800-1613 controls
CodeTitle
SCRM-COMP-1Component Authenticity
SCRM-COMP-2Software Bill of Materials Use
SCRM-COMP-3Provenance and Pedigree Tracking

Enterprise Governance

3 controls
Controls in the Enterprise Governance domain of NIST SP 800-1613 controls
CodeTitle
SCRM-GOV-1C-SCRM Governance Structure
SCRM-GOV-2C-SCRM Policy Framework
SCRM-GOV-3C-SCRM Strategy and Implementation Plan

Incident and Response

2 controls
Controls in the Incident and Response domain of NIST SP 800-1612 controls
CodeTitle
SCRM-INC-1Supply Chain Incident Response
SCRM-INC-2Vulnerability Disclosure and Response in Supply Chain

NIST SP 800-161: Access Control

5 controls

Logical and physical access controls (NIST SP 800-161)

Controls in the NIST SP 800-161: Access Control domain of NIST SP 800-1615 controls
CodeTitle
SP800-161-CONTROLS-ACICT SCRM Control Family: Access Control
SP800-161-CONTROLS-SAICT SCRM Control Family: System and Services Acquisition
SP800-161-CONTROLS-SRICT SCRM Control Family: Supply Chain Risk Management
SP800-161-INCIDENTSupply Chain Incident Management
SP800-161-PROVENANCEProvenance and Traceability

NIST SP 800-161: Asset Management

5 controls

Information asset management (NIST SP 800-161)

Controls in the NIST SP 800-161: Asset Management domain of NIST SP 800-1615 controls
CodeTitle
SP800-161-CRITICALITYCriticality Analysis
SP800-161-FOUND-PRACTICESFoundational ICT SCRM Practices
SP800-161-MONITORRisk Process: Monitor
SP800-161-RESPONDRisk Process: Respond
SP800-161-SUPPLIERSupplier Relationship Management

NIST SP 800-161: Communications Security

0 controls

Network and communications security (NIST SP 800-161)

NIST SP 800-161: Cryptography

0 controls

Cryptographic controls (NIST SP 800-161)

NIST SP 800-161: Information Security Policies

5 controls

Organizational information security policies (NIST SP 800-161)

Controls in the NIST SP 800-161: Information Security Policies domain of NIST SP 800-1615 controls
CodeTitle
SP800-161-ASSESSRisk Process: Assess
SP800-161-FRAMERisk Process: Frame
SP800-161-TIER1Multitiered Risk: Tier 1 (Organization)
SP800-161-TIER2Multitiered Risk: Tier 2 (Mission/Business Process)
SP800-161-TIER3Multitiered Risk: Tier 3 (Information Systems)

NIST SP 800-161: Operations Security

0 controls

Secure operations and monitoring (NIST SP 800-161)

Programme Measurement

1 controls
Controls in the Programme Measurement domain of NIST SP 800-1611 controls
CodeTitle
SCRM-MEAS-1C-SCRM Metrics and Reporting

Resilience

2 controls
Controls in the Resilience domain of NIST SP 800-1612 controls
CodeTitle
SCRM-RES-1Supply Chain Resilience and Continuity
SCRM-RES-2Supply Chain Information Sharing

Risk Management

2 controls
Controls in the Risk Management domain of NIST SP 800-1612 controls
CodeTitle
SCRM-RM-1Supply Chain Risk Assessment
SCRM-RM-2Criticality Analysis

Supplier Management

3 controls
Controls in the Supplier Management domain of NIST SP 800-1613 controls
CodeTitle
SCRM-SUP-1Supplier Due Diligence
SCRM-SUP-2Continuous Supplier Monitoring
SCRM-SUP-3Supplier Performance and Issue Management

Maps to 1 other framework

34 total controls
NIST SP 800-53 Rev 5
15 source controls mapped|11 target controls covered
44%

Frequently Asked Questions

What is NIST SP 800-161?

NIST SP 800-161 is a compliance framework from United States with 14 domains and 34 controls. Cybersecurity Supply Chain Risk Management Practices It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-161 have?

NIST SP 800-161 has 34 controls organised across 14 domains. The largest domains are NIST SP 800-161: Access Control (5 controls), NIST SP 800-161: Asset Management (5 controls), NIST SP 800-161: Information Security Policies (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-161 map to?

NIST SP 800-161 maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (44% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-161 compliance?

Start your NIST SP 800-161 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-161 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required