Supply Chain Management

From attackics
Revision as of 17:00, 12 April 2021 by Jsteele (talk | contribs) (Created page with "{{Mitigation |Name=Supply Chain Management |NIST Control=SA-12 |Technical Description=Implement a supply chain management program, including policies and procedures to ensure...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search
Supply Chain Management
Mitigation
ID M0817
NIST SP 800-53 Rev. 4 SA-12

Description

Implement a supply chain management program, including policies and procedures to ensure all devices and components originate from a trusted supplier and are tested to verify their integrity.


Techniques Addressed by Mitigation

NameUse
Supply Chain CompromiseA supply chain management program should include methods the assess the trustworthiness and technical maturity of a supplier, along with technical methods (e.g., code-signing, bill of materials) needed to validate the integrity of newly obtained devices and components. Develop procurement language that emphasizes the expectations for suppliers regarding the artifacts, audit records, and technical capabilities needed to validate the integrity of the device’s supply chain.1