id: "SR-05(02)" title: "Assessments Prior to Selection, Acceptance, Modification, or Update" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-05.02" priority: "P1" implementation_level: "organization" parent: "SR-05" enhancement: True
Statement
Assess the system, system component, or system service prior to selection, acceptance, modification, or update.
Guidance
Organizational personnel or independent, external entities conduct assessments of systems, components, products, tools, and services to uncover evidence of tampering, unintentional and intentional vulnerabilities, or evidence of non-compliance with supply chain controls. These include malicious code, malicious processes, defective software, backdoors, and counterfeits. Assessments can include evaluations; design proposal reviews; visual or physical inspection; static and dynamic analyses; visual, x-ray, or magnetic particle inspections; simulations; white, gray, or black box testing; fuzz testing; stress testing; and penetration testing (see SR-6(1) ). Evidence generated during assessments is documented for follow-on actions by organizations. The evidence generated during the organizational or independent assessments of supply chain elements may be used to improve supply chain processes and inform the supply chain risk management process. The evidence can be leveraged in follow-on assessments. Evidence and other documentation may be shared in accordance with organizational agreements.
Assessment Objective: the system, system component, or system service is assessed prior to selection;
Assessment Objective: the system, system component, or system service is assessed prior to acceptance;
Assessment Objective: the system, system component, or system service is assessed prior to modification;
Assessment Objective: the system, system component, or system service is assessed prior to update.
System security plan
system and services acquisition policy
procedures addressing supply chain protection
procedures addressing the integration of information security requirements into the acquisition process
security test and evaluation results
vulnerability assessment results
penetration testing results
organizational risk assessment results
system security plan
other relevant documents or records
Organizational personnel with system and services acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain protection responsibilities
Organizational processes for conducting assessments prior to selection, acceptance, or update
mechanisms supporting and/or implementing the conducting of assessments prior to selection, acceptance, or update