id: "RA-03(01)" title: "Supply Chain Risk Assessment" family: "RA" family_name: "Risk Assessment" sort_id: "ra-03.01" priority: "P1" implementation_level: "organization" parent: "RA-03" enhancement: True
Assess supply chain risks associated with {{ insert: param, ra-03.01_odp.01 }} ; and
Update the supply chain risk assessment {{ insert: param, ra-03.01_odp.02 }} , when there are significant changes to the relevant supply chain, or when changes to the system, environments of operation, or other conditions may necessitate a change in the supply chain.
Guidance
Supply chain-related events include disruption, use of defective components, insertion of counterfeits, theft, malicious development practices, improper delivery practices, and insertion of malicious code. These events can have a significant impact on the confidentiality, integrity, or availability of a system and its information and, therefore, can also adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. The supply chain-related events may be unintentional or malicious and can occur at any point during the system life cycle. An analysis of supply chain risk can help an organization identify systems or components for which additional supply chain risk mitigations are required.
Assessment Objective: supply chain risks associated with {{ insert: param, ra-03.01_odp.01 }} are assessed;
Assessment Objective: the supply chain risk assessment is updated {{ insert: param, ra-03.01_odp.02 }} , when there are significant changes to the relevant supply chain, or when changes to the system, environments of operation, or other conditions may necessitate a change in the supply chain.
Supply chain risk management policy
inventory of critical systems, system components, and system services
risk assessment policy
security planning policy and procedures
procedures addressing organizational assessments of supply chain risk
risk assessment
risk assessment results
risk assessment reviews
risk assessment updates
acquisition policy
system security plan
supply chain risk management plan
other relevant documents or records
Organizational personnel with risk assessment responsibilities
organizational personnel with security responsibilities
organizational personnel with supply chain risk management responsibilities
Organizational processes for risk assessment
mechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the supply chain risk assessment