Control statement
- a.Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services;
- b.Implement the supply chain risk management strategy consistently across the organization; and
- c.Review and update the supply chain risk management strategy on [Organization-defined: frequency] or as required, to address organizational changes.
Discussion
An organization-wide supply chain risk management strategy includes an unambiguous expression of the supply chain risk appetite and tolerance for the organization, acceptable supply chain risk mitigation strategies or controls, a process for consistently evaluating and monitoring supply chain risk, approaches for implementing and communicating the supply chain risk management strategy, and the associated roles and responsibilities. Supply chain risk management includes considerations of the security and privacy risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services. The supply chain risk management strategy can be incorporated into the organization’s overarching risk management strategy and can guide and inform supply chain policies and system-level supply chain risk management plans. In addition, the use of a risk executive function can facilitate a consistent, organization-wide application of the supply chain risk management strategy. The supply chain risk management strategy is implemented at the organization and mission/business levels, whereas the supply chain risk management plan (see [SR-2](#sr-2) ) is implemented at the system level.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Supply Chain Risk Management Strategy as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- program charters and policies
- governance meeting records
- risk and performance metrics
- resource and responsibility assignments
Common failure patterns
- program metrics count activity instead of outcomes
- system-level risks never reach enterprise governance
- responsibilities assigned without authority or resources
- privacy and security managed in separate silos
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PM-30a.
- PM-30a.[01]an organization-wide strategy for managing supply chain risks is developed;
- PM-30a.[02]the supply chain risk management strategy addresses risks associated with the development of systems;
- PM-30a.[03]the supply chain risk management strategy addresses risks associated with the development of system components;
- PM-30a.[04]the supply chain risk management strategy addresses risks associated with the development of system services;
- PM-30a.[05]the supply chain risk management strategy addresses risks associated with the acquisition of systems;
- PM-30a.[06]the supply chain risk management strategy addresses risks associated with the acquisition of system components;
- PM-30a.[07]the supply chain risk management strategy addresses risks associated with the acquisition of system services;
- PM-30a.[08]the supply chain risk management strategy addresses risks associated with the maintenance of systems;
- PM-30a.[09]the supply chain risk management strategy addresses risks associated with the maintenance of system components;
- PM-30a.[10]the supply chain risk management strategy addresses risks associated with the maintenance of system services;
- PM-30a.[11]the supply chain risk management strategy addresses risks associated with the disposal of systems;
- PM-30a.[12]the supply chain risk management strategy addresses risks associated with the disposal of system components;
- PM-30a.[13]the supply chain risk management strategy addresses risks associated with the disposal of system services;
- PM-30b.the supply chain risk management strategy is implemented consistently across the organization;
- PM-30c.the supply chain risk management strategy is reviewed and updated [Organization-defined: frequency] or as required to address organizational changes.
Examine
- Supply chain risk management strategy
- organizational risk management strategy
- enterprise risk management documents
- other relevant documents or records
Interview
- Organizational personnel with supply chain risk management responsibilities
- organizational personnel with information security responsibilities
- organizational personnel with acquisition responsibilities
- organizational personnel with enterprise risk management responsibilities
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PM-30(1) — Suppliers of Critical or Mission-essential Items
Identify, prioritize, and assess suppliers of critical or mission-essential technologies, products, and services.
Official discussion
The identification and prioritization of suppliers of critical or mission-essential technologies, products, and services is paramount to the mission/business success of organizations. The assessment of suppliers is conducted using supplier reviews (see [SR-6](#sr-6) ) and supply chain risk assessment processes (see [RA-3(1)](#ra-3.1) ). An analysis of supply chain risk can help an organization identify systems or components for which additional supply chain risk mitigations are required.
Assessment objectives and methods
- PM-30(01)[01]suppliers of critical or mission-essential technologies, products, and services are identified;
- PM-30(01)[02]suppliers of critical or mission-essential technologies, products, and services are prioritized;
- PM-30(01)[03]suppliers of critical or mission-essential technologies, products, and services are assessed.
Examine
- Supply chain risk management strategy
- organization-wide risk management strategy
- enterprise risk management documents
- inventory records or suppliers
- assessment and prioritization documentation
- critical or mission-essential technologies, products, and service documents or records
- other relevant documents or records
Interview
- Organizational personnel with supply chain risk management responsibilities
- organizational personnel with information security responsibilities
- organizational personnel with acquisition responsibilities
- organizational personnel with enterprise risk management responsibilities
Test
- Organizational processes for identifying, prioritizing, and assessing critical or mission-essential technologies, products, and services
- organizational processes for maintaining an inventory of suppliers
- organizational process for associating suppliers with critical or mission-essential technologies, products, and services
Related controls
Authoritative sources
- PRIVACT ↗
- FASC18 ↗
- EO 13873 ↗
- 41 CFR 201 ↗
- OMB A-130 ↗
- OMB M-17-06 ↗
- CNSSD 505 ↗
- ISO 27036 ↗
- ISO 20243 ↗
- SP 800-161 ↗
- IR 8272 ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.