id: "SR-04(04)" title: "Supply Chain Integrity — Pedigree" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-04.04" priority: "P1" implementation_level: "organization" parent: "SR-04" enhancement: True
Statement
Employ {{ insert: param, sr-04.04_odp.01 }} and conduct {{ insert: param, sr-04.04_odp.02 }} to ensure the integrity of the system and system components by validating the internal composition and provenance of critical or mission-essential technologies, products, and services.
Guidance
Authoritative information regarding the internal composition of system components and the provenance of technology, products, and services provides a strong basis for trust. The validation of the internal composition and provenance of technologies, products, and services is referred to as the pedigree. For microelectronics, this includes material composition of components. For software this includes the composition of open-source and proprietary code, including the version of the component at a given point in time. Pedigrees increase the assurance that the claims suppliers assert about the internal composition and provenance of the products, services, and technologies they provide are valid. The validation of the internal composition and provenance can be achieved by various evidentiary artifacts or records that manufacturers and suppliers produce during the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of technology, products, and services. Evidentiary artifacts include, but are not limited to, software identification (SWID) tags, software component inventory, the manufacturers’ declarations of platform attributes (e.g., serial numbers, hardware component inventory), and measurements (e.g., firmware hashes) that are tightly bound to the hardware itself.
Assessment Objective: {{ insert: param, sr-04.04_odp.01 }} are employed to ensure the integrity of the system and system components;
Assessment Objective: {{ insert: param, sr-04.04_odp.02 }} is conducted to ensure the integrity of the system and system components.
Supply chain risk management policy and procedures
supply chain risk management plan
system and services acquisition policy
procedures addressing supply chain protection
bill of materials for critical systems or system components
acquisition documentation
software identification tags
manufacturer declarations of platform attributes (e.g., serial numbers, hardware component inventory) and measurements (e.g., firmware hashes) that are tightly bound to the hardware itself
system security plan
other relevant documents or records
Organizational personnel with system and services acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
Organizational processes for identifying pedigree information
organizational processes to determine and validate the integrity of the internal composition of critical systems and critical system components
mechanisms to determine and validate the integrity of the internal composition of critical systems and critical system components