id: "SR-05(01)" title: "Adequate Supply" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-05.01" priority: "P1" implementation_level: "organization" parent: "SR-05" enhancement: True
Statement
Employ the following controls to ensure an adequate supply of {{ insert: param, sr-05.01_odp.02 }}: {{ insert: param, sr-05.01_odp.01 }}.
Guidance
Adversaries can attempt to impede organizational operations by disrupting the supply of critical system components or corrupting supplier operations. Organizations may track systems and component mean time to failure to mitigate the loss of temporary or permanent system function. Controls to ensure that adequate supplies of critical system components include the use of multiple suppliers throughout the supply chain for the identified critical components, stockpiling spare components to ensure operation during mission-critical times, and the identification of functionally identical or similar components that may be used, if necessary.
Assessment Objective
{{ insert: param, sr-05.01_odp.01 }} are employed to ensure an adequate supply of {{ insert: param, sr-05.01_odp.02 }}.
Supply chain risk management policy and procedures
supply chain risk management strategy
supply chain risk management plan
contingency planning documents
inventory of critical systems and system components
determination of adequate supply
system and services acquisition policy
procedures addressing supply chain protection
procedures addressing the integration of information security requirements into the acquisition process
procedures addressing the integration of acquisition strategies, contract tools, and procurement methods into the acquisition process
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for systems or services
purchase orders/requisitions for the system, system component, or system service from suppliers
system security plan
other relevant documents or records
Organizational personnel with system and services acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
Organizational processes for defining and employing tailored acquisition strategies, contract tools, and procurement methods
mechanisms supporting and/or implementing the definition and employment of tailored acquisition strategies, contract tools, and procurement methods