Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

SR-4 — Provenance

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

4Enhancements
1Parameters
0Baseline memberships
3Assessment methods

SR — Supply Chain Risk Management · NIST SP 800-53 Release 5.2.0

Official NIST control content

Control statement

Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [Organization-defined: systems, system components, and associated data].

Official NIST discussion

Discussion

Every system and system component has a point of origin and may be changed throughout its existence. Provenance is the chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include personnel and processes used to interact with or make modifications to the system, component, or associated data. Organizations consider developing procedures (see [SR-1](#sr-1) ) for allocating responsibilities for the creation, maintenance, and monitoring of provenance for systems and system components; transferring provenance documentation and responsibility between organizations; and preventing and monitoring for unauthorized changes to the provenance records. Organizations have methods to document, monitor, and maintain valid provenance baselines for systems, system components, and related data. These actions help track, assess, and document any changes to the provenance, including changes in supply chain elements or configuration, and help ensure non-repudiation of provenance information and the provenance change records. Provenance considerations are addressed throughout the system development life cycle and incorporated into contracts and other arrangements, as appropriate.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

systems, system components, and associated datasystems, system components, and associated data that require valid provenance are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Provenance as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to cybersecurity supply-chain governance, provenance, supplier risk, component authenticity, and dependency resilience.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • supplier inventories and criticality ratings
  • contract security clauses
  • provenance and authenticity records
  • supplier monitoring and incident records

Common failure patterns

  • tier-one vendors assessed while sub-tier dependencies are ignored
  • contracts lack evidence and notification obligations
  • open-source and service dependencies omitted
  • supplier risk reviews occur only at onboarding

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SR-04[01]valid provenance is documented for [Organization-defined: systems, system components, and associated data];
  2. SR-04[02]valid provenance is monitored for [Organization-defined: systems, system components, and associated data];
  3. SR-04[03]valid provenance is maintained for [Organization-defined: systems, system components, and associated data].

Examine

  • Supply chain risk management policy
  • supply chain risk management procedures
  • supply chain risk management plan
  • documentation of critical systems, critical system components, and associated data
  • documentation showing the history of ownership, custody, and location of and changes to critical systems or critical system components
  • system architecture
  • inter-organizational agreements and procedures
  • contracts
  • system security plan
  • privacy plan
  • personally identifiable information processing policy
  • other relevant documents or records

Interview

  • Organizational personnel with acquisition responsibilities
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel with supply chain risk management responsibilities

Test

  • Organizational processes for identifying the provenance of critical systems and critical system components
  • mechanisms used to document, monitor, or maintain provenance
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SR-4(1) — Identity

Establish and maintain unique identification of the following supply chain elements, processes, and personnel associated with the identified system and critical system components: [Organization-defined: supply chain elements, processes, and personnel].

Official discussion

Knowing who and what is in the supply chains of organizations is critical to gaining visibility into supply chain activities. Visibility into supply chain activities is also important for monitoring and identifying high-risk events and activities. Without reasonable visibility into supply chains elements, processes, and personnel, it is very difficult for organizations to understand and manage risk and reduce their susceptibility to adverse events. Supply chain elements include organizations, entities, or tools used for the research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of systems and system components. Supply chain processes include development processes for hardware, software, and firmware; shipping and handling procedures; configuration management tools, techniques, and measures to maintain provenance; personnel and physical security programs; or other programs, processes, or procedures associated with the production and distribution of supply chain elements. Supply chain personnel are individuals with specific roles and responsibilities related to the secure the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of a system or system component. Identification methods are sufficient to support an investigation in case of a supply chain change (e.g. if a supply company is purchased), compromise, or event.

Organization-defined parameters (1)
supply chain elements, processes, and personnelsupply chain elements, processes, and personnel associated with systems and critical system components that require unique identification are defined;
Assessment objectives and methods
  1. SR-04(01)[01]unique identification of [Organization-defined: supply chain elements, processes, and personnel] is established;
  2. SR-04(01)[02]unique identification of [Organization-defined: supply chain elements, processes, and personnel] is maintained.

Examine

  • Supply chain risk management policy and procedures
  • supply chain risk management plan
  • system and services acquisition policy
  • procedures addressing supply chain protection
  • procedures addressing the integration of information security requirements into the acquisition process
  • list of supply chain elements, processes, and actors (associated with the system, system component, or system service) requiring implementation of unique identification processes, procedures, tools, mechanisms, equipment, techniques, and/or configurations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system and services acquisition responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with supply chain protection responsibilities
  • organizational personnel with responsibilities for establishing and retaining the unique identification of supply chain elements, processes, and actors

Test

  • Organizational processes for defining, establishing, and retaining unique identification for supply chain elements, processes, and actors
  • mechanisms supporting and/or implementing the definition, establishment, and retention of unique identification for supply chain elements, processes, and actors
Related controls
Official NIST control enhancement

SR-4(2) — Track and Trace

Establish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [Organization-defined: systems and critical system components].

Official discussion

Tracking the unique identification of systems and system components during development and transport activities provides a foundational identity structure for the establishment and maintenance of provenance. For example, system components may be labeled using serial numbers or tagged using radio-frequency identification tags. Labels and tags can help provide better visibility into the provenance of a system or system component. A system or system component may have more than one unique identifier. Identification methods are sufficient to support a forensic investigation after a supply chain compromise or event.

Organization-defined parameters (1)
systems and critical system componentssystems and critical system components that require unique identification for tracking through the supply chain are defined;
Assessment objectives and methods
  1. SR-04(02)[01]the unique identification of [Organization-defined: systems and critical system components] is established for tracking through the supply chain;
  2. SR-04(02)[02]the unique identification of [Organization-defined: systems and critical system components] is maintained for tracking through the supply chain.

Examine

  • Supply chain risk management policy and procedures
  • system and services acquisition policy
  • procedures addressing supply chain protection
  • procedures addressing the integration of information security requirements into the acquisition process
  • supply chain risk management plan
  • list of supply chain elements, processes, and actors (associated with the system, system component, or system service) requiring implementation of unique identification processes, procedures, tools, mechanisms, equipment, techniques, and/or configurations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system and services acquisition responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with supply chain protection responsibilities
  • organizational personnel with responsibilities for establishing and retaining the unique identification of supply chain elements, processes, and actors

Test

  • Organizational processes for defining, establishing, and retaining unique identification for supply chain elements, processes, and actors
  • mechanisms supporting and/or implementing the definition, establishment, and retention of unique identification for supply chain elements, processes, and actors
Related controls
Official NIST control enhancement

SR-4(3) — Validate as Genuine and Not Altered

Employ the following controls to validate that the system or system component received is genuine and has not been altered: [Organization-defined: organization-defined controls].

Official discussion

For many systems and system components, especially hardware, there are technical means to determine if the items are genuine or have been altered, including optical and nanotechnology tagging, physically unclonable functions, side-channel analysis, cryptographic hash verifications or digital signatures, and visible anti-tamper labels or stickers. Controls can also include monitoring for out of specification performance, which can be an indicator of tampering or counterfeits. Organizations may leverage supplier and contractor processes for validating that a system or component is genuine and has not been altered and for replacing a suspect system or component. Some indications of tampering may be visible and addressable before accepting delivery, such as inconsistent packaging, broken seals, and incorrect labels. When a system or system component is suspected of being altered or counterfeit, the supplier, contractor, or original equipment manufacturer may be able to replace the item or provide a forensic capability to determine the origin of the counterfeit or altered item. Organizations can provide training to personnel on how to identify suspicious system or component deliveries.

Organization-defined parameters (3)
organization-defined controls
controlscontrols to validate that the system or system component received is genuine are defined;
controlscontrols to validate that the system or system component received has not been altered are defined;
Assessment objectives and methods
  1. SR-04(03)[01][Organization-defined: controls] are employed to validate that the system or system component received is genuine;
  2. SR-04(03)[02][Organization-defined: controls] are employed to validate that the system or system component received has not been altered.

Examine

  • Supply chain risk management policy and procedures
  • supply chain risk management plan
  • system and services acquisition policy
  • procedures addressing supply chain protection
  • procedures addressing the security design principle of trusted components used in the specification, design, development, implementation, and modification of the system
  • system design documentation
  • procedures addressing the integration of information security requirements into the acquisition process
  • solicitation documentation
  • acquisition documentation
  • service level agreements
  • acquisition contracts for the system, system component, or system service
  • evidentiary documentation (including applicable configurations) indicating that the system or system component is genuine and has not been altered
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system and services acquisition responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with supply chain risk management responsibilities

Test

  • Organizational processes for defining and employing validation safeguards
  • mechanisms supporting and/or implementing the definition and employment of validation safeguards
  • mechanisms supporting the application of the security design principle of trusted components in system specification, design, development, implementation, and modification
Related controls
Official NIST control enhancement

SR-4(4) — Supply Chain Integrity — Pedigree

Employ [Organization-defined: controls] and conduct [Organization-defined: analysis method] to ensure the integrity of the system and system components by validating the internal composition and provenance of critical or mission-essential technologies, products, and services.

Official discussion

Authoritative information regarding the internal composition of system components and the provenance of technology, products, and services provides a strong basis for trust. The validation of the internal composition and provenance of technologies, products, and services is referred to as the pedigree. For microelectronics, this includes material composition of components. For software this includes the composition of open-source and proprietary code, including the version of the component at a given point in time. Pedigrees increase the assurance that the claims suppliers assert about the internal composition and provenance of the products, services, and technologies they provide are valid. The validation of the internal composition and provenance can be achieved by various evidentiary artifacts or records that manufacturers and suppliers produce during the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of technology, products, and services. Evidentiary artifacts include, but are not limited to, software identification (SWID) tags, software component inventory, the manufacturers’ declarations of platform attributes (e.g., serial numbers, hardware component inventory), and measurements (e.g., firmware hashes) that are tightly bound to the hardware itself.

Organization-defined parameters (2)
controlscontrols employed to ensure that the integrity of the system and system component are defined;
analysis methodan analysis method to be conducted to validate the internal composition and provenance of critical or mission-essential technologies, products, and services to ensure the integrity of the system and system component is defined;
Assessment objectives and methods
  1. SR-04(04)[01][Organization-defined: controls] are employed to ensure the integrity of the system and system components;
  2. SR-04(04)[02][Organization-defined: analysis method] is conducted to ensure the integrity of the system and system components.

Examine

  • Supply chain risk management policy and procedures
  • supply chain risk management plan
  • system and services acquisition policy
  • procedures addressing supply chain protection
  • bill of materials for critical systems or system components
  • acquisition documentation
  • software identification tags
  • manufacturer declarations of platform attributes (e.g., serial numbers, hardware component inventory) and measurements (e.g., firmware hashes) that are tightly bound to the hardware itself
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system and services acquisition responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with supply chain risk management responsibilities

Test

  • Organizational processes for identifying pedigree information
  • organizational processes to determine and validate the integrity of the internal composition of critical systems and critical system components
  • mechanisms to determine and validate the integrity of the internal composition of critical systems and critical system components
Related controls
Source record

Authoritative sources