id: "SR-03(02)" title: "Limitation of Harm" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-03.02" priority: "P1" implementation_level: "organization" parent: "SR-03" enhancement: True
Statement
Employ the following controls to limit harm from potential adversaries identifying and targeting the organizational supply chain: {{ insert: param, sr-03.02_odp }}.
Guidance
Controls that can be implemented to reduce the probability of adversaries successfully identifying and targeting the supply chain include avoiding the purchase of custom or non-standardized configurations, employing approved vendor lists with standing reputations in industry, following pre-agreed maintenance schedules and update and patch delivery mechanisms, maintaining a contingency plan in case of a supply chain event, using procurement carve-outs that provide exclusions to commitments or obligations, using diverse delivery routes, and minimizing the time between purchase decisions and delivery.
Assessment Objective
{{ insert: param, sr-03.02_odp }} are employed to limit harm from potential adversaries identifying and targeting the organizational supply chain.
Supply chain risk management policy and procedures
supply chain risk management plan
system and services acquisition policy
configuration management policy
procedures addressing supply chain protection
procedures addressing the integration of information security requirements into the acquisition process
procedures addressing the baseline configuration of the system
configuration management plan
system design documentation
system architecture and associated configuration documentation
solicitation documentation
acquisition documentation
acquisition contracts for the system, system component, or system service
threat assessments
vulnerability assessments
list of security safeguards to be taken to protect the organizational supply chain against potential supply chain threats
system security plan
other relevant documents or records
Organizational personnel with system and services acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
Organizational processes for defining and employing safeguards to limit harm from adversaries of the organizational supply chain
mechanisms supporting and/or implementing the definition and employment of safeguards to protect the organizational supply chain