id: "IR-04(10)" title: "Supply Chain Coordination" family: "IR" family_name: "Incident Response" sort_id: "ir-04.10" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True
Statement
Coordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.
Guidance
Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Supply chain incidents can occur anywhere through or to the supply chain and include compromises or breaches that involve primary or sub-tier providers, information technology products, system components, development processes or personnel, and distribution processes or warehousing facilities. Organizations consider including processes for protecting and sharing incident information in information exchange agreements and their obligations for reporting incidents to government oversight bodies (e.g., Federal Acquisition Security Council).
Assessment Objective
incident handling activities involving supply chain events are coordinated with other organizations involved in the supply chain.
Incident response policy
procedures addressing supply chain coordination and supply chain risk information sharing with the Federal Acquisition Security Council
acquisition contracts
service-level agreements
incident response plan
supply chain risk management plan
system security plan
incident response plans of other organization involved in supply chain activities
other relevant documents or records
Organizational personnel with incident handling responsibilities
organizational personnel with mission and business responsibilities
organizational personnel with legal responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
organizational personnel with acquisition responsibilities