id: "SR-11(03)" title: "Anti-counterfeit Scanning" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-11.03" priority: "P1" implementation_level: "organization" parent: "SR-11" enhancement: True
Statement
Scan for counterfeit system components {{ insert: param, sr-11.03_odp }}.
Guidance
The type of component determines the type of scanning to be conducted (e.g., web application scanning if the component is a web application).
Assessment Objective
scanning for counterfeit system components is conducted {{ insert: param, sr-11.03_odp }}.
Supply chain risk management policy and procedures
supply chain risk management plan
anti-counterfeit policy and procedures
system design documentation
system configuration settings and associated documentation
scanning tools and associated documentation
scanning results
procedures addressing supply chain protection
acquisition documentation
inter-organizational agreements and procedures
system security plan
other relevant documents or records
Organizational personnel with system and services acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
organizational personnel with responsibilities for anti-counterfeit policies and procedures
organizational personnel with responsibility for anti-counterfeit scanning
Organizational processes for scanning for counterfeit system components
mechanisms supporting and/or implementing anti-counterfeit scanning