Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

SR-2 — Supply Chain Risk Management Plan

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

1Enhancements
2Parameters
3Baseline memberships
3Assessment methods

SR — Supply Chain Risk Management · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the following systems, system components or system services: [Organization-defined: systems, system components, or system services];
  2. b.Review and update the supply chain risk management plan [Organization-defined: frequency] or as required, to address threat, organizational or environmental changes; and
  3. c.Protect the supply chain risk management plan from unauthorized disclosure and modification.
Official NIST discussion

Discussion

The dependence on products, systems, and services from external providers, as well as the nature of the relationships with those providers, present an increasing level of risk to an organization. Threat actions that may increase security or privacy risks include unauthorized production, the insertion or use of counterfeits, tampering, theft, insertion of malicious software and hardware, and poor manufacturing and development practices in the supply chain. Supply chain risks can be endemic or systemic within a system element or component, a system, an organization, a sector, or the Nation. Managing supply chain risk is a complex, multifaceted undertaking that requires a coordinated effort across an organization to build trust relationships and communicate with internal and external stakeholders. Supply chain risk management (SCRM) activities include identifying and assessing risks, determining appropriate risk response actions, developing SCRM plans to document response actions, and monitoring performance against plans. The SCRM plan (at the system-level) is implementation specific, providing policy implementation, requirements, constraints and implications. It can either be stand-alone, or incorporated into system security and privacy plans. The SCRM plan addresses managing, implementation, and monitoring of SCRM controls and the development/sustainment of systems across the SDLC to support mission and business functions. Because supply chains can differ significantly across and within organizations, SCRM plans are tailored to the individual program, organizational, and operational contexts. Tailored SCRM plans provide the basis for determining whether a technology, service, system component, or system is fit for purpose, and as such, the controls need to be tailored accordingly. Tailored SCRM plans help organizations focus their resources on the most critical mission and business functions based on mission and business requirements and their risk environment. Supply chain risk management plans include an expression of the supply chain risk tolerance for the organization, acceptable supply chain risk mitigation strategies or controls, a process for consistently evaluating and monitoring supply chain risk, approaches for implementing and communicating the plan, a description of and justification for supply chain risk mitigation measures taken, and associated roles and responsibilities. Finally, supply chain risk management plans address requirements for developing trustworthy, secure, privacy-protective, and resilient system components and systems, including the application of the security design principles implemented as part of life cycle-based systems security engineering processes (see [SA-8](#sa-8)).

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

systems, system components, or system servicessystems, system components, or system services for which a supply chain risk management plan is developed are defined;
frequencythe frequency at which to review and update the supply chain risk management plan is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Supply Chain Risk Management Plan as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to cybersecurity supply-chain governance, provenance, supplier risk, component authenticity, and dependency resilience.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • supplier inventories and criticality ratings
  • contract security clauses
  • provenance and authenticity records
  • supplier monitoring and incident records

Common failure patterns

  • tier-one vendors assessed while sub-tier dependencies are ignored
  • contracts lack evidence and notification obligations
  • open-source and service dependencies omitted
  • supplier risk reviews occur only at onboarding

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SR-02a.
    1. SR-02a.[01]a plan for managing supply chain risks is developed;
    2. SR-02a.[02]the supply chain risk management plan addresses risks associated with the research and development of [Organization-defined: systems, system components, or system services];
    3. SR-02a.[03]the supply chain risk management plan addresses risks associated with the design of [Organization-defined: systems, system components, or system services];
    4. SR-02a.[04]the supply chain risk management plan addresses risks associated with the manufacturing of [Organization-defined: systems, system components, or system services];
    5. SR-02a.[05]the supply chain risk management plan addresses risks associated with the acquisition of [Organization-defined: systems, system components, or system services];
    6. SR-02a.[06]the supply chain risk management plan addresses risks associated with the delivery of [Organization-defined: systems, system components, or system services];
    7. SR-02a.[07]the supply chain risk management plan addresses risks associated with the integration of [Organization-defined: systems, system components, or system services];
    8. SR-02a.[08]the supply chain risk management plan addresses risks associated with the operation and maintenance of [Organization-defined: systems, system components, or system services];
    9. SR-02a.[09]the supply chain risk management plan addresses risks associated with the disposal of [Organization-defined: systems, system components, or system services];
  2. SR-02b.the supply chain risk management plan is reviewed and updated [Organization-defined: frequency] or as required to address threat, organizational, or environmental changes;
  3. SR-02c.
    1. SR-02c.[01]the supply chain risk management plan is protected from unauthorized disclosure;
    2. SR-02c.[02]the supply chain risk management plan is protected from unauthorized modification.

Examine

  • Supply chain risk management policy
  • supply chain risk management procedures
  • supply chain risk management plan
  • system and services acquisition policy
  • system and services acquisition procedures
  • procedures addressing supply chain protection
  • procedures for protecting the supply chain risk management plan from unauthorized disclosure and modification
  • system development life cycle procedures
  • procedures addressing the integration of information security and privacy requirements into the acquisition process
  • acquisition documentation
  • service level agreements
  • acquisition contracts for the system, system component, or system service
  • list of supply chain threats
  • list of safeguards to be taken against supply chain threats
  • system life cycle documentation
  • inter-organizational agreements and procedures
  • system security plan
  • privacy plan
  • privacy program plan
  • other relevant documents or records

Interview

  • Organizational personnel with acquisition responsibilities
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel with supply chain risk management responsibilities

Test

  • Organizational processes for defining and documenting the system development life cycle (SDLC)
  • organizational processes for identifying SDLC roles and responsibilities
  • organizational processes for integrating supply chain risk management into the SDLC
  • mechanisms supporting and/or implementing the SDLC
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SR-2(1) — Establish SCRM Team

LowModerateHigh

Establish a supply chain risk management team consisting of [Organization-defined: personnel, roles and responsibilities] to lead and support the following SCRM activities: [Organization-defined: supply chain risk management activities].

Official discussion

To implement supply chain risk management plans, organizations establish a coordinated, team-based approach to identify and assess supply chain risks and manage these risks by using programmatic and technical mitigation techniques. The team approach enables organizations to conduct an analysis of their supply chain, communicate with internal and external partners or stakeholders, and gain broad consensus regarding the appropriate resources for SCRM. The SCRM team consists of organizational personnel with diverse roles and responsibilities for leading and supporting SCRM activities, including risk executive, information technology, contracting, information security, privacy, mission or business, legal, supply chain and logistics, acquisition, business continuity, and other relevant functions. Members of the SCRM team are involved in various aspects of the SDLC and, collectively, have an awareness of and provide expertise in acquisition processes, legal practices, vulnerabilities, threats, and attack vectors, as well as an understanding of the technical aspects and dependencies of systems. The SCRM team can be an extension of the security and privacy risk management processes or be included as part of an organizational risk management team.

Organization-defined parameters (2)
personnel, roles and responsibilitiesthe personnel, roles, and responsibilities of the supply chain risk management team are defined;
supply chain risk management activitiessupply chain risk management activities are defined;
Assessment objectives and methods

a supply chain risk management team consisting of [Organization-defined: personnel, roles and responsibilities] is established to lead and support [Organization-defined: supply chain risk management activities].

Examine

  • Supply chain risk management policy
  • supply chain risk management procedures
  • supply chain risk management team charter documentation
  • supply chain risk management strategy
  • supply chain risk management implementation plan
  • procedures addressing supply chain protection
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with acquisition responsibilities
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel with supply chain risk management responsibilities
  • organizational personnel with enterprise risk management responsibilities
  • legal counsel
  • organizational personnel with business continuity responsibilities
Source record

Authoritative sources