id: "SR-11" title: "Component Authenticity" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-11" priority: "P1" implementation_level: "organization" enhancements: - sr-11.1 - sr-11.2 - sr-11.3


Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and

Report counterfeit system components to {{ insert: param, sr-11_odp.01 }}.

Guidance

Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include CISA.

Assessment Objective: an anti-counterfeit policy is developed and implemented;

Assessment Objective: anti-counterfeit procedures are developed and implemented;

Assessment Objective: the anti-counterfeit procedures include the means to detect counterfeit components entering the system;

Assessment Objective: the anti-counterfeit procedures include the means to prevent counterfeit components from entering the system;

Assessment Objective: counterfeit system components are reported to {{ insert: param, sr-11_odp.01 }}.

Supply chain risk management policy and procedures

supply chain risk management plan

system and services acquisition policy

anti-counterfeit plan

anti-counterfeit policy and procedures

media disposal policy

media protection policy

incident response policy

reports notifying developers, manufacturers, vendors, contractors, and/or external reporting organizations of counterfeit system components

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

inter-organizational agreements and procedures

records of reported counterfeit system components

system security plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

organizational personnel with responsibilities for anti-counterfeit policies, procedures, and reporting

Organizational processes for counterfeit prevention, detection, and reporting

mechanisms supporting and/or implementing anti-counterfeit detection, prevention, and reporting