id: "IR-04(10)" title: "Supply Chain Coordination" family: "IR" family_name: "Incident Response" sort_id: "ir-04.10" priority: "P2" implementation_level: "organization" parent: "IR-04" enhancement: True


Statement

Coordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.

Guidance

Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Supply chain incidents can occur anywhere through or to the supply chain and include compromises or breaches that involve primary or sub-tier providers, information technology products, system components, development processes or personnel, and distribution processes or warehousing facilities. Organizations consider including processes for protecting and sharing incident information in information exchange agreements and their obligations for reporting incidents to government oversight bodies (e.g., Federal Acquisition Security Council).

Assessment Objective

incident handling activities involving supply chain events are coordinated with other organizations involved in the supply chain.

Incident response policy

procedures addressing supply chain coordination and supply chain risk information sharing with the Federal Acquisition Security Council

acquisition contracts

service-level agreements

incident response plan

supply chain risk management plan

system security plan

incident response plans of other organization involved in supply chain activities

other relevant documents or records

Organizational personnel with incident handling responsibilities

organizational personnel with mission and business responsibilities

organizational personnel with legal responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

organizational personnel with acquisition responsibilities