id: "SR-11" title: "Component Authenticity" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-11" priority: "P1" implementation_level: "organization" enhancements: - sr-11.1 - sr-11.2 - sr-11.3
Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and
Report counterfeit system components to {{ insert: param, sr-11_odp.01 }}.
Guidance
Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include CISA.
Assessment Objective: an anti-counterfeit policy is developed and implemented;
Assessment Objective: anti-counterfeit procedures are developed and implemented;
Assessment Objective: the anti-counterfeit procedures include the means to detect counterfeit components entering the system;
Assessment Objective: the anti-counterfeit procedures include the means to prevent counterfeit components from entering the system;
Assessment Objective: counterfeit system components are reported to {{ insert: param, sr-11_odp.01 }}.
Supply chain risk management policy and procedures
supply chain risk management plan
system and services acquisition policy
anti-counterfeit plan
anti-counterfeit policy and procedures
media disposal policy
media protection policy
incident response policy
reports notifying developers, manufacturers, vendors, contractors, and/or external reporting organizations of counterfeit system components
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
inter-organizational agreements and procedures
records of reported counterfeit system components
system security plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
organizational personnel with responsibilities for anti-counterfeit policies, procedures, and reporting
Organizational processes for counterfeit prevention, detection, and reporting
mechanisms supporting and/or implementing anti-counterfeit detection, prevention, and reporting