id: "SR-02(01)" title: "Establish SCRM Team" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-02.01" priority: "P1" implementation_level: "organization" parent: "SR-02" enhancement: True
Statement
Establish a supply chain risk management team consisting of {{ insert: param, sr-02.01_odp.01 }} to lead and support the following SCRM activities: {{ insert: param, sr-02.01_odp.02 }}.
Guidance
To implement supply chain risk management plans, organizations establish a coordinated, team-based approach to identify and assess supply chain risks and manage these risks by using programmatic and technical mitigation techniques. The team approach enables organizations to conduct an analysis of their supply chain, communicate with internal and external partners or stakeholders, and gain broad consensus regarding the appropriate resources for SCRM. The SCRM team consists of organizational personnel with diverse roles and responsibilities for leading and supporting SCRM activities, including risk executive, information technology, contracting, information security, privacy, mission or business, legal, supply chain and logistics, acquisition, business continuity, and other relevant functions. Members of the SCRM team are involved in various aspects of the SDLC and, collectively, have an awareness of and provide expertise in acquisition processes, legal practices, vulnerabilities, threats, and attack vectors, as well as an understanding of the technical aspects and dependencies of systems. The SCRM team can be an extension of the security and privacy risk management processes or be included as part of an organizational risk management team.
Assessment Objective
a supply chain risk management team consisting of {{ insert: param, sr-02.01_odp.01 }} is established to lead and support {{ insert: param, sr-02.01_odp.02 }}.
Supply chain risk management policy
supply chain risk management procedures
supply chain risk management team charter documentation
supply chain risk management strategy
supply chain risk management implementation plan
procedures addressing supply chain protection
system security plan
privacy plan
other relevant documents or records
Organizational personnel with acquisition responsibilities
organizational personnel with information security and privacy responsibilities
organizational personnel with supply chain risk management responsibilities
organizational personnel with enterprise risk management responsibilities
legal counsel
organizational personnel with business continuity responsibilities