id: "SR-03" title: "Supply Chain Controls and Processes" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-03" priority: "P1" implementation_level: "system" enhancements: - sr-3.1 - sr-3.2 - sr-3.3
Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of {{ insert: param, sr-03_odp.01 }} in coordination with {{ insert: param, sr-03_odp.02 }};
Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events: {{ insert: param, sr-03_odp.03 }} ; and
Document the selected and implemented supply chain processes and controls in {{ insert: param, sr-03_odp.04 }}.
Guidance
Supply chain elements include organizations, entities, or tools employed for the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of systems and system components. Supply chain processes include hardware, software, and firmware development processes; shipping and handling procedures; personnel security and physical security programs; configuration management tools, techniques, and measures to maintain provenance; or other programs, processes, or procedures associated with the development, acquisition, maintenance and disposal of systems and system components. Supply chain elements and processes may be provided by organizations, system integrators, or external providers. Weaknesses or deficiencies in supply chain elements or processes represent potential vulnerabilities that can be exploited by adversaries to cause harm to the organization and affect its ability to carry out its core missions or business functions. Supply chain personnel are individuals with roles and responsibilities in the supply chain.
Assessment Objective: a process or processes is/are established to identify and address weaknesses or deficiencies in the supply chain elements and processes of {{ insert: param, sr-03_odp.01 }};
Assessment Objective: the process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of {{ insert: param, sr-03_odp.01 }} is/are coordinated with {{ insert: param, sr-03_odp.02 }};
Assessment Objective: {{ insert: param, sr-03_odp.03 }} are employed to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events;
Assessment Objective: the selected and implemented supply chain processes and controls are documented in {{ insert: param, sr-03_odp.04 }}.
Supply chain risk management policy
supply chain risk management procedures
supply chain risk management strategy
supply chain risk management plan
systems and critical system components inventory documentation
system and services acquisition policy
system and services acquisition procedures
procedures addressing the integration of information security and privacy requirements into the acquisition process
solicitation documentation
acquisition documentation (including purchase orders)
service level agreements
acquisition contracts for systems or services
risk register documentation
system security plan
privacy plan
other relevant documents or records
Organizational personnel with acquisition responsibilities
organizational personnel with information security and privacy responsibilities
organizational personnel with supply chain risk management responsibilities
Organizational processes for identifying and addressing supply chain element and process deficiencies