SUPPLY CHAINSIGNAL

Read the network. Decide with context.

Authority library

Standards and authority record

Each record preserves the issuing authority, jurisdiction, instrument or authority type, legal or operating status, version and application dates, affected audience, workflow mapping, source link, and interpretation boundary.

Organizations managing cybersecurity risks in technology products and services · U.S. federal cybersecurity guidance

NIST SP 800-161 Rev. 1

The publication integrates cybersecurity supply-chain risk management into enterprise risk activities and provides strategy, plan, assessment, and control guidance.

Organizations choosing to implement a business continuity management system · International management-system standard

ISO 22301:2019

ISO 22301 specifies requirements for a management system intended to prepare for, respond to, and recover from disruptions.

Organizations seeking principles for resilience · International guidance standard

ISO 22316:2017

ISO 22316 provides principles and attributes for organizational resilience rather than a certifiable requirements system.

Organizations managing security risks including supply-chain activities · International management-system standard

ISO 28000:2022

ISO 28000 specifies requirements for a security management system relevant to organizations and supply chains.

Organizations designing risk-management processes · International guidance standard

ISO 31000:2018

ISO 31000 provides principles and guidelines for integrating risk management into governance, strategy, planning, and operations.

Organizations integrating sustainability into procurement · International guidance standard

ISO 20400:2017

ISO 20400 provides guidance for integrating sustainability into procurement policy, strategy, process, and supplier relationships.

Organizations managing collaborative business relationships · International management-system standard

ISO 44001:2017

ISO 44001 specifies requirements for identifying, developing, managing, and exiting collaborative business relationships.

Multinational enterprises and organizations applying responsible-business due diligence · Intergovernmental due-diligence guidance

OECD Due Diligence Guidance

The guidance describes risk-based due diligence across policies, impact identification, prevention and mitigation, tracking, communication, and remediation.

States and business enterprises addressing human-rights impacts · Intergovernmental principles

UN Guiding Principles

The principles describe the state duty to protect, corporate responsibility to respect human rights, and access to remedy.

Companies within the directive's scope and phased application as transposed by Member States · European Union directive

EU CSDDD

The directive establishes a corporate due-diligence framework for specified human-rights and environmental impacts across defined chains of activities.

Operators and traders placing or exporting covered commodities and products, subject to scope and timing · European Union regulation

EU Deforestation Regulation

The regulation creates due-diligence and geolocation duties for specified commodities and products associated with deforestation and legality criteria.

Products placed or made available on the EU market or exported from the EU, under the regulation's investigation and enforcement structure · European Union regulation

EU Forced Labour Regulation

The regulation establishes an EU framework to investigate and prohibit products made with forced labour.

Organizations managing ICT supply-chain risk · U.S. federal guidance and resource library

CISA ICT SCRM Resources

CISA maintains ICT supply-chain risk resources developed with public and private stakeholders.

Importers and supply chains subject to UFLPA and customs enforcement · U.S. federal enforcement strategy

UFLPA Strategy

The strategy describes enforcement, entity listing, risk assessment, and importer guidance under UFLPA.

Customs administrations and authorized economic operator programs adopting the framework · Intergovernmental customs framework

WCO SAFE Framework

The framework sets customs-to-customs, customs-to-business, and customs-to-other-government cooperation principles for secure and facilitated trade.

How to read the library

Binding requirements, official guidance, technical standards, implementation guides, program rules, and authority data are not interchangeable. Each page names the source class and states what it can and cannot establish about an organization or product.