How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?
Begin with a risk scenario that connects a threat event, vulnerability or exposure, affected supplier, product, service, or supply-chain path, likelihood, and impact. State the time horizon and assumptions. Consider criticality, concentration, substitutability, dependencies, recovery or replacement time, and effects on missions, systems, data, people, other organizations, and the Nation where relevant.
Compare responses against risk appetite and , mission priorities, applicable law and contracts, cost, feasibility, dependencies, and decision authority. Acceptance keeps the identified exposure without further risk-reducing action because the authorized owner judges the remaining risk acceptable. Avoidance removes the activity or exposure. Mitigation changes likelihood or impact through controls. Sharing or transfer reallocates some responsibility or financial consequence through arrangements such as contracts or insurance, but it does not automatically remove operational, mission, legal, or reputational exposure.
Mitigation can include alternate sources, contract changes, added inspection or testing, segmentation, reduced access, patching, inventory buffers, recovery measures, or increased monitoring. State which part of the scenario each action changes and how effectiveness will be measured. Listing controls without that connection does not explain the response.
- Confirm that the risk statement and assessment are specific enough for a decision and identify uncertainty that could change the result.
- Document alternatives considered, the selected course, the authority making the decision, and why the is within that authority's tolerance.
- Translate the response into funded acquisition, contract, engineering, security, monitoring, and contingency actions with owners, milestones, dependencies, and measures.
- Escalate risk above tolerance, outside the owner's authority, or aggregated across several systems or missions to the appropriate mission/business or enterprise authority.
Section 2.3.4 and Appendix G's Respond step cover alternative courses of action, risk response across all three levels, tailored controls, acceptable risk, and documented C-SCRM plans and POA&Ms.