03.17.03: Supply Chain Requirements and Processes
Control Familly: Supply Chain Risk Management
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-30 [55]
SP 800-161 [33]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.17.03
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
SR-03
a. Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes.
b. Enforce the following security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events: [Assignment: organization-defined security requirements].
Discussion:
Supply chain elements include organizations, entities, or tools that are employed for the research, development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of systems and system components. Supply chain processes include hardware, software, firmware, and systems development processes; shipping and handling procedures; physical security programs; personnel security programs; configuration management tools, techniques, and measures to maintain provenance; or other programs, processes, or procedures associated with the development, acquisition, maintenance, and disposal of systems and system components. Supply chain elements and processes are provided by organizations, system integrators, or external service providers. Weaknesses or deficiencies in supply chain elements or processes represent potential vulnerabilities that can be exploited by adversaries to harm the organization and affect its ability to carry out its core missions or business functions.
Assessment Methods and Objectives
Examine [SELECT FROM: SCRM policy and procedures; SCRM strategy; SCRM plan; systems and critical system components inventory documentation; system and services acquisition policy and procedures; procedures for the integration of security requirements into the acquisition process; solicitation documentation; acquisition documentation (including purchase orders); shipping and handling procedures; configuration management documentation and records; acquisition contracts for systems or services; service-level agreements; risk register documentation; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with acquisition responsibilities; personnel with information security responsibilities; personnel with SCRM responsibilities]
Test [SELECT FROM: processes for identifying and addressing supply chain element and process deficiencies]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.17.03.ODP[01]: security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events are defined.
A.03.17.03.a[01]: a process for identifying weaknesses or deficiencies in the supply chain elements and processes is established.
A.03.17.03.a[02]: a process for addressing weaknesses or deficiencies in the supply chain elements and processes is established.
A.03.17.03.b: the following security requirements are enforced to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences of supply chain-related events: <A.03.17.03.ODP[01]: security requirements>.
The Security Requirements
NIST SP 800-171r3 (USA) & ITSP.10.171 (Canada)
3.5. Identification and Authentication
3.12. Security Assessment and Monitoring
3.13. System and Communications Protection
3.14. System and Information Integrity
3.16. System and Services Acquisition
3.17. Supply Chain Risk Management
CMMC 3.0 - N/A
CPCSC - N/A