id: "SR-03(02)" title: "Limitation of Harm" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-03.02" priority: "P1" implementation_level: "organization" parent: "SR-03" enhancement: True


Statement

Employ the following controls to limit harm from potential adversaries identifying and targeting the organizational supply chain: {{ insert: param, sr-03.02_odp }}.

Guidance

Controls that can be implemented to reduce the probability of adversaries successfully identifying and targeting the supply chain include avoiding the purchase of custom or non-standardized configurations, employing approved vendor lists with standing reputations in industry, following pre-agreed maintenance schedules and update and patch delivery mechanisms, maintaining a contingency plan in case of a supply chain event, using procurement carve-outs that provide exclusions to commitments or obligations, using diverse delivery routes, and minimizing the time between purchase decisions and delivery.

Assessment Objective

{{ insert: param, sr-03.02_odp }} are employed to limit harm from potential adversaries identifying and targeting the organizational supply chain.

Supply chain risk management policy and procedures

supply chain risk management plan

system and services acquisition policy

configuration management policy

procedures addressing supply chain protection

procedures addressing the integration of information security requirements into the acquisition process

procedures addressing the baseline configuration of the system

configuration management plan

system design documentation

system architecture and associated configuration documentation

solicitation documentation

acquisition documentation

acquisition contracts for the system, system component, or system service

threat assessments

vulnerability assessments

list of security safeguards to be taken to protect the organizational supply chain against potential supply chain threats

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

Organizational processes for defining and employing safeguards to limit harm from adversaries of the organizational supply chain

mechanisms supporting and/or implementing the definition and employment of safeguards to protect the organizational supply chain