Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PM-30 — Supply Chain Risk Management Strategy

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

1Enhancements
1Parameters
0Baseline memberships
2Assessment methods

PM — Program Management · NIST SP 800-53 Release 5.2.0

Official NIST control content

Control statement

  1. a.Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services;
  2. b.Implement the supply chain risk management strategy consistently across the organization; and
  3. c.Review and update the supply chain risk management strategy on [Organization-defined: frequency] or as required, to address organizational changes.
Official NIST discussion

Discussion

An organization-wide supply chain risk management strategy includes an unambiguous expression of the supply chain risk appetite and tolerance for the organization, acceptable supply chain risk mitigation strategies or controls, a process for consistently evaluating and monitoring supply chain risk, approaches for implementing and communicating the supply chain risk management strategy, and the associated roles and responsibilities. Supply chain risk management includes considerations of the security and privacy risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services. The supply chain risk management strategy can be incorporated into the organization’s overarching risk management strategy and can guide and inform supply chain policies and system-level supply chain risk management plans. In addition, the use of a risk executive function can facilitate a consistent, organization-wide application of the supply chain risk management strategy. The supply chain risk management strategy is implemented at the organization and mission/business levels, whereas the supply chain risk management plan (see [SR-2](#sr-2) ) is implemented at the system level.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

frequencythe frequency for reviewing and updating the supply chain risk management strategy is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Supply Chain Risk Management Strategy as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • program charters and policies
  • governance meeting records
  • risk and performance metrics
  • resource and responsibility assignments

Common failure patterns

  • program metrics count activity instead of outcomes
  • system-level risks never reach enterprise governance
  • responsibilities assigned without authority or resources
  • privacy and security managed in separate silos

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PM-30a.
    1. PM-30a.[01]an organization-wide strategy for managing supply chain risks is developed;
    2. PM-30a.[02]the supply chain risk management strategy addresses risks associated with the development of systems;
    3. PM-30a.[03]the supply chain risk management strategy addresses risks associated with the development of system components;
    4. PM-30a.[04]the supply chain risk management strategy addresses risks associated with the development of system services;
    5. PM-30a.[05]the supply chain risk management strategy addresses risks associated with the acquisition of systems;
    6. PM-30a.[06]the supply chain risk management strategy addresses risks associated with the acquisition of system components;
    7. PM-30a.[07]the supply chain risk management strategy addresses risks associated with the acquisition of system services;
    8. PM-30a.[08]the supply chain risk management strategy addresses risks associated with the maintenance of systems;
    9. PM-30a.[09]the supply chain risk management strategy addresses risks associated with the maintenance of system components;
    10. PM-30a.[10]the supply chain risk management strategy addresses risks associated with the maintenance of system services;
    11. PM-30a.[11]the supply chain risk management strategy addresses risks associated with the disposal of systems;
    12. PM-30a.[12]the supply chain risk management strategy addresses risks associated with the disposal of system components;
    13. PM-30a.[13]the supply chain risk management strategy addresses risks associated with the disposal of system services;
  2. PM-30b.the supply chain risk management strategy is implemented consistently across the organization;
  3. PM-30c.the supply chain risk management strategy is reviewed and updated [Organization-defined: frequency] or as required to address organizational changes.

Examine

  • Supply chain risk management strategy
  • organizational risk management strategy
  • enterprise risk management documents
  • other relevant documents or records

Interview

  • Organizational personnel with supply chain risk management responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with acquisition responsibilities
  • organizational personnel with enterprise risk management responsibilities
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PM-30(1) — Suppliers of Critical or Mission-essential Items

Identify, prioritize, and assess suppliers of critical or mission-essential technologies, products, and services.

Official discussion

The identification and prioritization of suppliers of critical or mission-essential technologies, products, and services is paramount to the mission/business success of organizations. The assessment of suppliers is conducted using supplier reviews (see [SR-6](#sr-6) ) and supply chain risk assessment processes (see [RA-3(1)](#ra-3.1) ). An analysis of supply chain risk can help an organization identify systems or components for which additional supply chain risk mitigations are required.

Assessment objectives and methods
  1. PM-30(01)[01]suppliers of critical or mission-essential technologies, products, and services are identified;
  2. PM-30(01)[02]suppliers of critical or mission-essential technologies, products, and services are prioritized;
  3. PM-30(01)[03]suppliers of critical or mission-essential technologies, products, and services are assessed.

Examine

  • Supply chain risk management strategy
  • organization-wide risk management strategy
  • enterprise risk management documents
  • inventory records or suppliers
  • assessment and prioritization documentation
  • critical or mission-essential technologies, products, and service documents or records
  • other relevant documents or records

Interview

  • Organizational personnel with supply chain risk management responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with acquisition responsibilities
  • organizational personnel with enterprise risk management responsibilities

Test

  • Organizational processes for identifying, prioritizing, and assessing critical or mission-essential technologies, products, and services
  • organizational processes for maintaining an inventory of suppliers
  • organizational process for associating suppliers with critical or mission-essential technologies, products, and services
Related controls
Source record

Authoritative sources