Standards and authority record
Each record preserves the issuing authority, jurisdiction, instrument or authority type, legal or operating status, version and application dates, affected audience, workflow mapping, source link, and interpretation boundary.
NIST SP 800-161 Rev. 1
The publication integrates cybersecurity supply-chain risk management into enterprise risk activities and provides strategy, plan, assessment, and control guidance.
ISO 22301:2019
ISO 22301 specifies requirements for a management system intended to prepare for, respond to, and recover from disruptions.
ISO 22316:2017
ISO 22316 provides principles and attributes for organizational resilience rather than a certifiable requirements system.
ISO 28000:2022
ISO 28000 specifies requirements for a security management system relevant to organizations and supply chains.
ISO 31000:2018
ISO 31000 provides principles and guidelines for integrating risk management into governance, strategy, planning, and operations.
ISO 20400:2017
ISO 20400 provides guidance for integrating sustainability into procurement policy, strategy, process, and supplier relationships.
ISO 44001:2017
ISO 44001 specifies requirements for identifying, developing, managing, and exiting collaborative business relationships.
OECD Due Diligence Guidance
The guidance describes risk-based due diligence across policies, impact identification, prevention and mitigation, tracking, communication, and remediation.
UN Guiding Principles
The principles describe the state duty to protect, corporate responsibility to respect human rights, and access to remedy.
EU CSDDD
The directive establishes a corporate due-diligence framework for specified human-rights and environmental impacts across defined chains of activities.
EU Deforestation Regulation
The regulation creates due-diligence and geolocation duties for specified commodities and products associated with deforestation and legality criteria.
EU Forced Labour Regulation
The regulation establishes an EU framework to investigate and prohibit products made with forced labour.
CISA ICT SCRM Resources
CISA maintains ICT supply-chain risk resources developed with public and private stakeholders.
UFLPA Strategy
The strategy describes enforcement, entity listing, risk assessment, and importer guidance under UFLPA.
WCO SAFE Framework
The framework sets customs-to-customs, customs-to-business, and customs-to-other-government cooperation principles for secure and facilitated trade.
How to read the library
Binding requirements, official guidance, technical standards, implementation guides, program rules, and authority data are not interchangeable. Each page names the source class and states what it can and cannot establish about an organization or product.