Control statement
- a.Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Organization-defined: system or system component] in coordination with [Organization-defined: supply chain personnel];
- b.Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events: [Organization-defined: supply chain controls] ; and
- c.Document the selected and implemented supply chain processes and controls in [Organization-defined: sr-03_odp.04].
Discussion
Supply chain elements include organizations, entities, or tools employed for the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of systems and system components. Supply chain processes include hardware, software, and firmware development processes; shipping and handling procedures; personnel security and physical security programs; configuration management tools, techniques, and measures to maintain provenance; or other programs, processes, or procedures associated with the development, acquisition, maintenance and disposal of systems and system components. Supply chain elements and processes may be provided by organizations, system integrators, or external providers. Weaknesses or deficiencies in supply chain elements or processes represent potential vulnerabilities that can be exploited by adversaries to cause harm to the organization and affect its ability to carry out its core missions or business functions. Supply chain personnel are individuals with roles and responsibilities in the supply chain.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Supply Chain Controls and Processes as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to cybersecurity supply-chain governance, provenance, supplier risk, component authenticity, and dependency resilience.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- supplier inventories and criticality ratings
- contract security clauses
- provenance and authenticity records
- supplier monitoring and incident records
Common failure patterns
- tier-one vendors assessed while sub-tier dependencies are ignored
- contracts lack evidence and notification obligations
- open-source and service dependencies omitted
- supplier risk reviews occur only at onboarding
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SR-03a.
- SR-03a.[01]a process or processes is/are established to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Organization-defined: system or system component];
- SR-03a.[02]the process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Organization-defined: system or system component] is/are coordinated with [Organization-defined: supply chain personnel];
- SR-03b.[Organization-defined: supply chain controls] are employed to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events;
- SR-03c.the selected and implemented supply chain processes and controls are documented in [Organization-defined: sr-03_odp.04].
Examine
- Supply chain risk management policy
- supply chain risk management procedures
- supply chain risk management strategy
- supply chain risk management plan
- systems and critical system components inventory documentation
- system and services acquisition policy
- system and services acquisition procedures
- procedures addressing the integration of information security and privacy requirements into the acquisition process
- solicitation documentation
- acquisition documentation (including purchase orders)
- service level agreements
- acquisition contracts for systems or services
- risk register documentation
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with acquisition responsibilities
- organizational personnel with information security and privacy responsibilities
- organizational personnel with supply chain risk management responsibilities
Test
- Organizational processes for identifying and addressing supply chain element and process deficiencies
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SR-3(1) — Diverse Supply Base
Employ a diverse set of sources for the following system components and services: [Organization-defined: organization-defined system components and services].
Official discussion
Diversifying the supply of systems, system components, and services can reduce the probability that adversaries will successfully identify and target the supply chain and can reduce the impact of a supply chain event or compromise. Identifying multiple suppliers for replacement components can reduce the probability that the replacement component will become unavailable. Employing a diverse set of developers or logistics service providers can reduce the impact of a natural disaster or other supply chain event. Organizations consider designing the system to include diverse materials and components.
Organization-defined parameters (3)
Assessment objectives and methods
- SR-03(01)[01]a diverse set of sources is employed for [Organization-defined: system components];
- SR-03(01)[02]a diverse set of sources is employed for [Organization-defined: services].
Examine
- Supply chain risk management policy and procedures
- system and services acquisition policy
- planning policy
- procedures addressing supply chain protection
- physical inventory of critical systems and system components
- inventory of critical suppliers, service providers, developers, and contracts
- inventory records of critical system components
- list of security safeguards ensuring an adequate supply of critical system components
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system and services acquisition responsibilities
- organizational personnel with information security responsibilities
- organizational personnel with supply chain protection responsibilities
Test
- Organizational processes for defining and employing security safeguards to ensure an adequate supply of critical system components
- processes to identify critical suppliers
- mechanisms supporting and/or implementing the security safeguards that ensure an adequate supply of critical system components
SR-3(2) — Limitation of Harm
Employ the following controls to limit harm from potential adversaries identifying and targeting the organizational supply chain: [Organization-defined: controls].
Official discussion
Controls that can be implemented to reduce the probability of adversaries successfully identifying and targeting the supply chain include avoiding the purchase of custom or non-standardized configurations, employing approved vendor lists with standing reputations in industry, following pre-agreed maintenance schedules and update and patch delivery mechanisms, maintaining a contingency plan in case of a supply chain event, using procurement carve-outs that provide exclusions to commitments or obligations, using diverse delivery routes, and minimizing the time between purchase decisions and delivery.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: controls] are employed to limit harm from potential adversaries identifying and targeting the organizational supply chain.
Examine
- Supply chain risk management policy and procedures
- supply chain risk management plan
- system and services acquisition policy
- configuration management policy
- procedures addressing supply chain protection
- procedures addressing the integration of information security requirements into the acquisition process
- procedures addressing the baseline configuration of the system
- configuration management plan
- system design documentation
- system architecture and associated configuration documentation
- solicitation documentation
- acquisition documentation
- acquisition contracts for the system, system component, or system service
- threat assessments
- vulnerability assessments
- list of security safeguards to be taken to protect the organizational supply chain against potential supply chain threats
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system and services acquisition responsibilities
- organizational personnel with information security responsibilities
- organizational personnel with supply chain risk management responsibilities
Test
- Organizational processes for defining and employing safeguards to limit harm from adversaries of the organizational supply chain
- mechanisms supporting and/or implementing the definition and employment of safeguards to protect the organizational supply chain
SR-3(3) — Sub-tier Flow Down
Ensure that the controls included in the contracts of prime contractors are also included in the contracts of subcontractors.
Official discussion
To manage supply chain risk effectively and holistically, it is important that organizations ensure that supply chain risk management controls are included at all tiers in the supply chain. This includes ensuring that Tier 1 (prime) contractors have implemented processes to facilitate the "flow down" of supply chain risk management controls to sub-tier contractors. The controls subject to flow down are identified in [SR-3b](#sr-3_smt.b).
Assessment objectives and methods
the controls included in the contracts of prime contractors are also included in the contracts of subcontractors.
Examine
- Supply chain risk management policy and procedures
- supply chain risk management plan
- system and services acquisition policy
- procedures addressing supply chain protection
- acquisition documentation
- service level agreements
- acquisition contracts for the system, system component, or system service
- inter-organizational agreements and procedures
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system and services acquisition responsibilities
- organizational personnel with information security responsibilities
- organizational personnel with supply chain risk management responsibilities
Test
- Organizational processes for establishing inter-organizational agreements and procedures with supply chain entities
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.