id: "SR-11(03)" title: "Anti-counterfeit Scanning" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-11.03" priority: "P1" implementation_level: "organization" parent: "SR-11" enhancement: True


Statement

Scan for counterfeit system components {{ insert: param, sr-11.03_odp }}.

Guidance

The type of component determines the type of scanning to be conducted (e.g., web application scanning if the component is a web application).

Assessment Objective

scanning for counterfeit system components is conducted {{ insert: param, sr-11.03_odp }}.

Supply chain risk management policy and procedures

supply chain risk management plan

anti-counterfeit policy and procedures

system design documentation

system configuration settings and associated documentation

scanning tools and associated documentation

scanning results

procedures addressing supply chain protection

acquisition documentation

inter-organizational agreements and procedures

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

organizational personnel with responsibilities for anti-counterfeit policies and procedures

organizational personnel with responsibility for anti-counterfeit scanning

Organizational processes for scanning for counterfeit system components

mechanisms supporting and/or implementing anti-counterfeit scanning