id: "IR-06(03)" title: "Supply Chain Coordination" family: "IR" family_name: "Incident Response" sort_id: "ir-06.03" priority: "P2" implementation_level: "organization" parent: "IR-06" enhancement: True


Statement

Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.

Guidance

Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Entities that provide supply chain governance include the Federal Acquisition Security Council (FASC). Supply chain incidents include compromises or breaches that involve information technology products, system components, development processes or personnel, distribution processes, or warehousing facilities. Organizations determine the appropriate information to share and consider the value gained from informing external organizations about supply chain incidents, including the ability to improve processes or to identify the root cause of an incident.

Assessment Objective

incident information is provided to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.

Incident response policy

procedures addressing supply chain coordination and supply chain risk information sharing with the Federal Acquisition Security Council

acquisition policy

acquisition contracts

service-level agreements

incident response plan

supply chain risk management plan

system security plan

plans of other organizations involved in supply chain activities

other relevant documents or records

Organizational personnel with incident reporting responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

organization personnel with acquisition responsibilities

Organizational processes for incident reporting

organizational processes for supply chain risk information sharing

mechanisms supporting and/or implementing the reporting of incident information involved in the supply chain