03.17.02: Acquisition Strategies, Tools, and Methods
Control Familly: Supply Chain Risk Management
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-30 [55]
SP 800-161 [33]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.17.02
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
SR-05
Develop and implement acquisition strategies, contract tools, and procurement methods to identify, protect against, and mitigate supply chain risks.
Discussion:
The acquisition process provides an important vehicle for protecting the supply chain. There are many useful tools and techniques available, including obscuring the end use of a system or system component, using blind purchases, requiring tamper-evident packaging, or using trusted or controlled distribution. The results from a supply chain risk assessment can inform the strategies, tools, and methods that are most applicable to the situation. Tools and techniques may provide protections against unauthorized production, theft, tampering, the insertion of counterfeits, the insertion of malicious software or backdoors, and poor development practices throughout the system life cycle.
Organizations also consider providing incentives for suppliers to implement safeguards, promote transparency in their processes and security practices, provide contract language that addresses the prohibition of tainted or counterfeit components, and restrict purchases from untrustworthy suppliers. Organizations consider providing training, education, and awareness programs for personnel regarding supply chain risks, available mitigation strategies, and when the programs should be employed. Methods for reviewing and protecting development plans, documentation, and evidence are commensurate with the security requirements of the organization. Contracts may specify documentation protection requirements.
Assessment Methods and Objectives
Examine [SELECT FROM: SCRM policy and procedures; SCRM plan; system and services acquisition policy and procedures; procedures for supply chain protection; procedures for the integration of information security requirements into the acquisition process; solicitation documentation; acquisition documentation (including purchase orders); service-level agreements; acquisition contracts for the system, system components, or services; documentation of identified supply chain risks; mitigation plans for supply chain risks; documentation of training, education, and awareness programs for personnel regarding supply chain risk; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with acquisition responsibilities; personnel with SCRM responsibilities; personnel with information security responsibilities]
Test [SELECT FROM: processes for defining and employing tailored acquisition strategies, contract tools, and procurement methods; mechanisms for implementing tailored acquisition strategies, contract tools, and procurement methods]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.17.02[01]: acquisition strategies, contract tools, and procurement methods are developed to identify supply chain risks.
A.03.17.02[02]: acquisition strategies, contract tools, and procurement methods are developed to protect against supply chain risks.
A.03.17.02[03]: acquisition strategies, contract tools, and procurement methods are developed to mitigate supply chain risks.
A.03.17.02[04]: acquisition strategies, contract tools, and procurement methods are implemented to identify supply chain risks.
A.03.17.02[05]: acquisition strategies, contract tools, and procurement methods are implemented to protect against supply chain risks.
A.03.17.02[06]: acquisition strategies, contract tools, and procurement methods are implemented to mitigate supply chain risks.
The Security Requirements
NIST SP 800-171r3 (USA) & ITSP.10.171 (Canada)
3.5. Identification and Authentication
3.12. Security Assessment and Monitoring
3.13. System and Communications Protection
3.14. System and Information Integrity
3.16. System and Services Acquisition
3.17. Supply Chain Risk Management
CMMC 3.0 - N/A
CPCSC - N/A