supply chain risk
nounid
4291·updated Aug 30, 2026verified· unreviewed
A risk measured by the likelihood and severity of damage if an Information Technology or Operations Technology system is compromised by a supply chain attack, and takes into account the importance of the system and the impact of compromise on organizational operations and assets, individuals, other organizations, and the Nation. Supply chain attacks may involve manipulating computing system hardware, software, or services at any point during the life cycle. Supply chain attacks are typically conducted or facilitated by individuals or organizations that have access through commercial ties, leading to stolen critical data and technology, corruption of the system/ infrastructure, and/or disabling of mission-critical operations.
MWE
Attested in
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
03.11.01.a03.17.0103.17.01.a03.17.01.b03.17.01.c03.17.01.c ¶ 103.17.01.c ¶ 103.17.01.c ¶ 203.17.02 ¶ 103.17.02 ¶ 203.17.02 ¶ 303.17.03.b3.2.1 ¶ 60
Classifications
Entity Type
Threat0%rule-basedmulti_axis_classifier_low_confidence.v1
Sensitivity
Regulated85%llm-generatedllm:claude-haiku-4-5
Information Class
unclassified
Variants
- synonym
- factor that may increase risk from supply chain attacks
- plural
- supply chain risks
- possessive
- supply chain risk's
- pluralpossessive
- supply chain risks'
Framework definitions
- §1
- A risk measured by the likelihood and severity of damage if an Information Technology or Operations Technology system is compromised by a supply chain attack, and takes into account the importance of the system and the impact of compromise on organizational operations and assets, individuals, other organizations, and the Nation. Supply chain attacks may involve manipulating computing system hardware, software, or services at any point during the life cycle. Supply chain attacks are typically conducted or facilitated by individuals or organizations that have access through commercial ties, leading to stolen critical data and technology, corruption of the system/ infrastructure, and/or disabling of mission-critical operations.
- §1 · attested_usage_pack_match
- No definition is given in NIST SP 800-171r3. The term is attested in use at 12 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · legacy_primary
- A risk measured by the likelihood and severity of damage if an Information Technology or Operations Technology system is compromised by a supply chain attack, and takes into account the importance of the system and the impact of compromise on organizational operations and assets, individuals, other organizations, and the Nation. Supply chain attacks may involve manipulating computing system hardware, software, or services at any point during the life cycle. Supply chain attacks are typically conducted or facilitated by individuals or organizations that have access through commercial ties, leading to stolen critical data and technology, corruption of the system/ infrastructure, and/or disabling of mission-critical operations.DR-088 backfill from the noun definition column
Outgoing relationships
No outgoing triples
This term is not the subject of any RDF-style relationship yet.
Incoming relationships
No incoming triples
No other term currently asserts a relationship to this one.