Policy and Procedures SR-1
Supply Chain Risk Management · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SR-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Supply Chain Risk Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SR-1 (Supply Chain Risk Management Policy and Procedures) is the paperwork foundation for the whole SR (Supply Chain Risk Management) family. SCRM stands for Supply Chain Risk Management — the risk that rides in with the software, hardware, and services you buy and the people you buy them from. This control asks you to write down, and keep current, a policy that says how your organization manages that risk, plus the procedures that put the policy into practice. It sits in the Low baseline, so every system needs it.
What good looks like
- Write a policy that states the purpose, scope, roles, responsibilities, and management commitment for supply chain risk — and say how it lines up with the laws and rules you follow.
- Write procedures that carry the policy out — the actual steps people take when buying, onboarding, or retiring a supplier or component.
- Name an official (a real person or role) who owns the policy and procedures and keeps them moving.
- Review and update on a schedule (for example, yearly) and also after big events — a breach, a new law, or a major change to what you buy.
- Keep the policy at the right level — it can live at the organization, mission, or single-system level, whichever fits.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
- CIS Controls v8 — Control 15 — Service Provider Management
How to move it toward Implemented
- Draft a one-page supply chain risk policy for this server: which suppliers and software sources are in scope, who approves them, and how risk is judged.
- Write the matching procedure — how a new package repository, vendor, or component gets vetted, approved, and recorded before it touches the server.
- Name the owner and set a review date (for example, review every 12 months), and record the last-reviewed date right on the document.
- Attach that policy-and-procedure document as hardening evidence on the asset, naming
SR-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.