id: "SR-05(02)" title: "Assessments Prior to Selection, Acceptance, Modification, or Update" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-05.02" priority: "P1" implementation_level: "organization" parent: "SR-05" enhancement: True


Statement

Assess the system, system component, or system service prior to selection, acceptance, modification, or update.

Guidance

Organizational personnel or independent, external entities conduct assessments of systems, components, products, tools, and services to uncover evidence of tampering, unintentional and intentional vulnerabilities, or evidence of non-compliance with supply chain controls. These include malicious code, malicious processes, defective software, backdoors, and counterfeits. Assessments can include evaluations; design proposal reviews; visual or physical inspection; static and dynamic analyses; visual, x-ray, or magnetic particle inspections; simulations; white, gray, or black box testing; fuzz testing; stress testing; and penetration testing (see SR-6(1) ). Evidence generated during assessments is documented for follow-on actions by organizations. The evidence generated during the organizational or independent assessments of supply chain elements may be used to improve supply chain processes and inform the supply chain risk management process. The evidence can be leveraged in follow-on assessments. Evidence and other documentation may be shared in accordance with organizational agreements.

Assessment Objective: the system, system component, or system service is assessed prior to selection;

Assessment Objective: the system, system component, or system service is assessed prior to acceptance;

Assessment Objective: the system, system component, or system service is assessed prior to modification;

Assessment Objective: the system, system component, or system service is assessed prior to update.

System security plan

system and services acquisition policy

procedures addressing supply chain protection

procedures addressing the integration of information security requirements into the acquisition process

security test and evaluation results

vulnerability assessment results

penetration testing results

organizational risk assessment results

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain protection responsibilities

Organizational processes for conducting assessments prior to selection, acceptance, or update

mechanisms supporting and/or implementing the conducting of assessments prior to selection, acceptance, or update