Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-172 Enhanced CUI Protection Center

03.17 — Supply Chain Risk Management

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

5Active requirements
12Parameters
12Assessment objectives

CUI requirement family

Supply Chain Risk Management

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

5 active0 withdrawnRevision 3
SR

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.17.01EActive

Notification Agreements

Establishing agreements and procedures facilitates communications among supply chain entities. Early notification of compromises and potential compromises in the supply chain that may adversely affect or have adversely affected organizational systems or system components is essential for organizations to effectively respond to such incidents. The results of assessments or audits may include open-source information th

03.17.02EActive

Inspection of Systems or Components

Inspecting systems or systems components for evidence of tampering addresses physical and logical tampering and is applied to systems and system components that are removed from organization-controlled areas. Indications of a need for inspection include changes in packaging, specifications, factory location, or entity in which the part is purchased, and when individuals return from travel to high-risk locations. This

03.17.03EActive

Component Authenticity

Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include the Cybersecurity and Infrastructure Security Agency (CISA). This requirement is sourced to a control tailored out of the SP 800-53B .13

03.17.04EActive

Provenance

Every system and system component has a point of origin and may be changed throughout its existence. Provenance is the chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include personnel and processes used to interact with or make modifications to the system, component, or associated data. Organizations have methods to document, mo

03.17.05EActive

Supply Chain Integrity – Pedigree

Authoritative information regarding the internal composition of system components and the provenance of technology, products, and services provides a strong basis for trust. The validation of the internal composition and provenance of technologies, products, and services is referred to as the pedigree. For microelectronics, this includes the material composition of components. For software this includes the compositi