risk

Malicious supply-chain injection of tampered hardware/software

Adversary creates false-front suppliers or intercepts the supply chain to insert counterfeit or tampered hardware, corrupted software/firmware, or malicious components into products and information systems.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

category
cyber_security
domain
  • Third-Party / Supply-Chain Risk
  • Secure Development (SDLC) & Application Security
  • Secure Configuration & Change Management
taxonomy
  • nist-800-30-threat-event
  • nist-800-30-threat-source
  • iso-27005-threat
inherent_rating
high

Details

risk_id
tprm-supply-chain-injection
category
cyber_security
likelihood
low
impact
critical
inherent_rating
high
treatment
mitigate
taxonomies
  • nist-800-30-threat-event
  • nist-800-30-threat-source
  • iso-27005-threat

Source

No record-specific source URL is provided.

Connections