id: "SR-10" title: "Inspection of Systems or Components" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-10" priority: "P1" implementation_level: "organization"
Statement
Inspect the following systems or system components {{ insert: param, sr-10_odp.02 }} to detect tampering: {{ insert: param, sr-10_odp.01 }}.
Guidance
The inspection of systems or systems components for tamper resistance and detection addresses physical and logical tampering and is applied to systems and system components removed from organization-controlled areas. Indications of a need for inspection include changes in packaging, specifications, factory location, or entity in which the part is purchased, and when individuals return from travel to high-risk locations.
Assessment Objective
{{ insert: param, sr-10_odp.01 }} are inspected {{ insert: param, sr-10_odp.02 }} to detect tampering.
Supply chain risk management policy and procedures
supply chain risk management plan
system and services acquisition policy
records of random inspections
inspection reports/results
assessment reports/results
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
inter-organizational agreements and procedures
system security plan
other relevant documents or records
Organizational personnel with system and services acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
Organizational processes for establishing inter-organizational agreements and procedures with supply chain entities
organizational processes to inspect for tampering