id: "SR-05(01)" title: "Adequate Supply" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-05.01" priority: "P1" implementation_level: "organization" parent: "SR-05" enhancement: True


Statement

Employ the following controls to ensure an adequate supply of {{ insert: param, sr-05.01_odp.02 }}: {{ insert: param, sr-05.01_odp.01 }}.

Guidance

Adversaries can attempt to impede organizational operations by disrupting the supply of critical system components or corrupting supplier operations. Organizations may track systems and component mean time to failure to mitigate the loss of temporary or permanent system function. Controls to ensure that adequate supplies of critical system components include the use of multiple suppliers throughout the supply chain for the identified critical components, stockpiling spare components to ensure operation during mission-critical times, and the identification of functionally identical or similar components that may be used, if necessary.

Assessment Objective

{{ insert: param, sr-05.01_odp.01 }} are employed to ensure an adequate supply of {{ insert: param, sr-05.01_odp.02 }}.

Supply chain risk management policy and procedures

supply chain risk management strategy

supply chain risk management plan

contingency planning documents

inventory of critical systems and system components

determination of adequate supply

system and services acquisition policy

procedures addressing supply chain protection

procedures addressing the integration of information security requirements into the acquisition process

procedures addressing the integration of acquisition strategies, contract tools, and procurement methods into the acquisition process

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for systems or services

purchase orders/requisitions for the system, system component, or system service from suppliers

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

Organizational processes for defining and employing tailored acquisition strategies, contract tools, and procurement methods

mechanisms supporting and/or implementing the definition and employment of tailored acquisition strategies, contract tools, and procurement methods