id: "SR-04(04)" title: "Supply Chain Integrity — Pedigree" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-04.04" priority: "P1" implementation_level: "organization" parent: "SR-04" enhancement: True


Statement

Employ {{ insert: param, sr-04.04_odp.01 }} and conduct {{ insert: param, sr-04.04_odp.02 }} to ensure the integrity of the system and system components by validating the internal composition and provenance of critical or mission-essential technologies, products, and services.

Guidance

Authoritative information regarding the internal composition of system components and the provenance of technology, products, and services provides a strong basis for trust. The validation of the internal composition and provenance of technologies, products, and services is referred to as the pedigree. For microelectronics, this includes material composition of components. For software this includes the composition of open-source and proprietary code, including the version of the component at a given point in time. Pedigrees increase the assurance that the claims suppliers assert about the internal composition and provenance of the products, services, and technologies they provide are valid. The validation of the internal composition and provenance can be achieved by various evidentiary artifacts or records that manufacturers and suppliers produce during the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of technology, products, and services. Evidentiary artifacts include, but are not limited to, software identification (SWID) tags, software component inventory, the manufacturers’ declarations of platform attributes (e.g., serial numbers, hardware component inventory), and measurements (e.g., firmware hashes) that are tightly bound to the hardware itself.

Assessment Objective: {{ insert: param, sr-04.04_odp.01 }} are employed to ensure the integrity of the system and system components;

Assessment Objective: {{ insert: param, sr-04.04_odp.02 }} is conducted to ensure the integrity of the system and system components.

Supply chain risk management policy and procedures

supply chain risk management plan

system and services acquisition policy

procedures addressing supply chain protection

bill of materials for critical systems or system components

acquisition documentation

software identification tags

manufacturer declarations of platform attributes (e.g., serial numbers, hardware component inventory) and measurements (e.g., firmware hashes) that are tightly bound to the hardware itself

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

Organizational processes for identifying pedigree information

organizational processes to determine and validate the integrity of the internal composition of critical systems and critical system components

mechanisms to determine and validate the integrity of the internal composition of critical systems and critical system components