id: "SR-04(03)" title: "Validate as Genuine and Not Altered" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-04.03" priority: "P1" implementation_level: "organization" parent: "SR-04" enhancement: True


Statement

Employ the following controls to validate that the system or system component received is genuine and has not been altered: {{ insert: param, sr-4.3_prm_1 }}.

Guidance

For many systems and system components, especially hardware, there are technical means to determine if the items are genuine or have been altered, including optical and nanotechnology tagging, physically unclonable functions, side-channel analysis, cryptographic hash verifications or digital signatures, and visible anti-tamper labels or stickers. Controls can also include monitoring for out of specification performance, which can be an indicator of tampering or counterfeits. Organizations may leverage supplier and contractor processes for validating that a system or component is genuine and has not been altered and for replacing a suspect system or component. Some indications of tampering may be visible and addressable before accepting delivery, such as inconsistent packaging, broken seals, and incorrect labels. When a system or system component is suspected of being altered or counterfeit, the supplier, contractor, or original equipment manufacturer may be able to replace the item or provide a forensic capability to determine the origin of the counterfeit or altered item. Organizations can provide training to personnel on how to identify suspicious system or component deliveries.

Assessment Objective: {{ insert: param, sr-04.03_odp.01 }} are employed to validate that the system or system component received is genuine;

Assessment Objective: {{ insert: param, sr-04.03_odp.02 }} are employed to validate that the system or system component received has not been altered.

Supply chain risk management policy and procedures

supply chain risk management plan

system and services acquisition policy

procedures addressing supply chain protection

procedures addressing the security design principle of trusted components used in the specification, design, development, implementation, and modification of the system

system design documentation

procedures addressing the integration of information security requirements into the acquisition process

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

evidentiary documentation (including applicable configurations) indicating that the system or system component is genuine and has not been altered

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

Organizational processes for defining and employing validation safeguards

mechanisms supporting and/or implementing the definition and employment of validation safeguards

mechanisms supporting the application of the security design principle of trusted components in system specification, design, development, implementation, and modification