id: "SR-10" title: "Inspection of Systems or Components" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-10" priority: "P1" implementation_level: "organization"


Statement

Inspect the following systems or system components {{ insert: param, sr-10_odp.02 }} to detect tampering: {{ insert: param, sr-10_odp.01 }}.

Guidance

The inspection of systems or systems components for tamper resistance and detection addresses physical and logical tampering and is applied to systems and system components removed from organization-controlled areas. Indications of a need for inspection include changes in packaging, specifications, factory location, or entity in which the part is purchased, and when individuals return from travel to high-risk locations.

Assessment Objective

{{ insert: param, sr-10_odp.01 }} are inspected {{ insert: param, sr-10_odp.02 }} to detect tampering.

Supply chain risk management policy and procedures

supply chain risk management plan

system and services acquisition policy

records of random inspections

inspection reports/results

assessment reports/results

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

inter-organizational agreements and procedures

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

Organizational processes for establishing inter-organizational agreements and procedures with supply chain entities

organizational processes to inspect for tampering