PlumbTrackLive demoGRC Risk System

← control library

Component Authenticity SR-11

Supply Chain Risk Management · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SR-11 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Supply Chain Risk Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SR-11 (Component Authenticity) is about keeping counterfeit parts — fake hardware, tampered firmware, or software that only pretends to be a trusted package — out of your system, and having a plan to report a counterfeit if one turns up. It belongs to the Supply Chain Risk Management (SR) family and sits in the Low baseline. The rule of thumb is simple: only run parts you can prove are the real thing, from a source you trust.

What good looks like

Framework mapping

How to move it toward Implemented