Security requirement
- a.Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes.
- b.Enforce the following security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events: [Organization-defined: security requirements].
Discussion
Supply chain elements include organizations, entities, or tools that are employed for the research, development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of systems and system components. Supply chain processes include hardware, software, firmware, and systems development processes; shipping and handling procedures; physical security programs; personnel security programs; configuration management tools, techniques, and measures to maintain provenance; or other programs, processes, or procedures associated with the development, acquisition, maintenance, and disposal of systems and system components. Supply chain elements and processes are provided by organizations, system integrators, or external service providers. Weaknesses or deficiencies in supply chain elements or processes represent potential vulnerabilities that can be exploited by adversaries to harm the organization and affect its ability to carry out its core missions or business functions.
Tailoring decisions required
Resolve these values through the governing organization’s approved tailoring and risk-management process before declaring the requirement implemented.
Implementation perspective
Treat Supply Chain Requirements and Processes as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to supply-chain governance, provenance, supplier risk, component authenticity, and dependency resilience.
- Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
- Resolve every organization-defined parameter through an approved governance and tailoring process.
- Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
- Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
- Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.
Questions to ask
- Which CUI assets, data flows, users, and services are protected by this requirement?
- Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
- Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
- What change, incident, or threshold should trigger reassessment?
Evidence and validation
- supplier inventories and criticality ratings
- contract security clauses
- provenance and authenticity records
- supplier monitoring and incident records
Common failure patterns
- sub-tier dependencies ignored
- contracts lacking evidence and notification obligations
- open-source and service dependencies omitted
- supplier risk reviewed only during procurement
Assessment objectives and methods
Assessment objectives (3)
- a.
a process for identifying weaknesses or deficiencies in the supply chain elements and processes is established.
- a.
a process for addressing weaknesses or deficiencies in the supply chain elements and processes is established.
- b.
the following security requirements are enforced to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences of supply chain-related events: [Organization-defined: security requirements].
Examine
- SCRM policy and procedures
- SCRM strategy
- SCRM plan
- systems and critical system components inventory documentation
- system and services acquisition policy and procedures
- procedures for the integration of security requirements into the acquisition process
- solicitation documentation
- acquisition documentation (including purchase orders)
- shipping and handling procedures
- configuration management documentation and records
- acquisition contracts for systems or services
- service-level agreements
- risk register documentation
- system security plan
- other relevant documents or records
Interview
- personnel with acquisition responsibilities
- personnel with information security responsibilities
- personnel with SCRM responsibilities
Test
- processes for identifying and addressing supply chain element and process deficiencies
Source NIST SP 800-53 controls
These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.
Authoritative sources
- NIST SP 800-171 Revision 3 official publication ↗
- NIST SP 800-171A Revision 3 official publication ↗
- NIST OSCAL Content release used for this import ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. The official publications, the responsible federal agency, and the governing contract or agreement determine applicability, tailoring, assessment depth, and required implementation.