id: "IR-06(03)" title: "Supply Chain Coordination" family: "IR" family_name: "Incident Response" sort_id: "ir-06.03" priority: "P2" implementation_level: "organization" parent: "IR-06" enhancement: True
Statement
Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.
Guidance
Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Entities that provide supply chain governance include the Federal Acquisition Security Council (FASC). Supply chain incidents include compromises or breaches that involve information technology products, system components, development processes or personnel, distribution processes, or warehousing facilities. Organizations determine the appropriate information to share and consider the value gained from informing external organizations about supply chain incidents, including the ability to improve processes or to identify the root cause of an incident.
Assessment Objective
incident information is provided to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.
Incident response policy
procedures addressing supply chain coordination and supply chain risk information sharing with the Federal Acquisition Security Council
acquisition policy
acquisition contracts
service-level agreements
incident response plan
supply chain risk management plan
system security plan
plans of other organizations involved in supply chain activities
other relevant documents or records
Organizational personnel with incident reporting responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
organization personnel with acquisition responsibilities
Organizational processes for incident reporting
organizational processes for supply chain risk information sharing
mechanisms supporting and/or implementing the reporting of incident information involved in the supply chain