id: "PL-08(02)" title: "Supplier Diversity" family: "PL" family_name: "Planning" sort_id: "pl-08.02" priority: "P1" implementation_level: "organization" parent: "PL-08" enhancement: True


Statement

Require that {{ insert: param, pl-08.02_odp.01 }} allocated to {{ insert: param, pl-08.02_odp.02 }} are obtained from different suppliers.

Guidance

Information technology products have different strengths and weaknesses. Providing a broad spectrum of products complements the individual offerings. For example, vendors offering malicious code protection typically update their products at different times, often developing solutions for known viruses, Trojans, or worms based on their priorities and development schedules. By deploying different products at different locations, there is an increased likelihood that at least one of the products will detect the malicious code. With respect to privacy, vendors may offer products that track personally identifiable information in systems. Products may use different tracking methods. Using multiple products may result in more assurance that personally identifiable information is inventoried.

Assessment Objective

{{ insert: param, pl-08.02_odp.01 }} that are allocated to {{ insert: param, pl-08.02_odp.02 }} are required to be obtained from different suppliers.

Security and privacy planning policy

procedures addressing information security and privacy architecture development

enterprise architecture documentation

information security and privacy architecture documentation

system security plan

privacy plan

security and privacy CONOPS for the system

IT acquisitions policy

other relevant documents or records

Organizational personnel with security and privacy planning and plan implementation responsibilities

organizational personnel with information security and privacy architecture development responsibilities

organizational personnel with acquisition responsibilities

organizational personnel with information security and privacy responsibilities

Organizational processes for obtaining information security and privacy safeguards from different suppliers