PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SR-3 — Supply Chain Controls and Processes

Framework: NIST SP 800-53 Rev.5 SR-3 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Does a documented Supply Chain Risk Management (SCRM) process exist that identifies and addresses weaknesses or deficiencies across the full lifecycle of supply chain elements (development, manufacturing, packaging, delivery, integration, operations, maintenance, and disposal) for the organization-defined systems and components in scope? (SR-3a)
Examine Is a current inventory of suppliers, service providers, and their supplied products/components maintained and classified by criticality or risk so that supply chain controls can be prioritized to the most critical elements? (aligns with CIS Control v8 15.1/15.2 service provider inventory and classification) (SR-3a)
Examine Are specific supply chain controls selected, mapped to identified risks, and shown to limit harm from supply-chain events (e.g., acquisition restricted to authorized/trusted sources, provenance/pedigree tracking, anti-counterfeit and tamper-evident measures, component authenticity verification)? (SR-3b)
Examine Are the selected and implemented supply chain processes and controls documented in the security and privacy plan, the SCRM plan, or another organization-defined document, and is that documentation current and approved? (SR-3c)
Interview Can SCRM or acquisition personnel describe how a discovered supply chain weakness (e.g., a supplier breach, counterfeit part, or end-of-life/unsupported component) is triaged, remediated, and escalated, including who holds the defined roles and responsibilities?
Interview Do procurement/contracting staff confirm that security and supply-chain requirements flow down to sub-tier (lower-level) suppliers and contractors, and can they explain how supplier compliance is enforced and monitored? (aligns with CIS Control v8 15.4 contractual security requirements)
Test For a sample of recent acquisitions of critical components, observe evidence that the documented supply chain controls were actually applied (e.g., authorized-source verification, provenance record, receiving inspection or tamper check, and a completed vendor/supplier risk assessment on file)?