Supply Chain Risk Management Plan SR-2
Supply Chain Risk Management · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SR-2 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Supply Chain Risk Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SR-2 (Supply Chain Risk Management Plan) turns the SR-1 policy into a concrete plan for this system. SCRM stands for Supply Chain Risk Management — the risk that comes in with the things you buy and the people you buy them from. The plan covers the whole life of a component: research, design, build, buy, deliver, integrate, run, maintain, and dispose. It is a Low-baseline control, and because the plan itself maps your weak points, you also have to protect it.
What good looks like
- Write a plan that names the supply chain risks for this system and how you will handle them across the component’s whole life — from purchase to disposal.
- Cover the real stages: acquisition, delivery, integration, operation and maintenance, and secure disposal — not just the day you install something.
- Review and update the plan on a set schedule, or sooner when the threat, the organization, or the environment changes.
- Protect the plan itself from unauthorized viewing or editing — it lays out your soft spots, so it is not a public document.
- Tie the plan back to the SR-1 policy so the two do not drift apart.
Framework mapping
- NIST CSF 2.0 — GV.SC-01 — A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
How to move it toward Implemented
- Write a short supply chain risk plan for this server: list the key suppliers and software sources, the risk each brings, and your response for each.
- Add a disposal step — how disks are wiped and hardware is retired — so the plan covers end-of-life, not just setup.
- Store the plan with restricted access (for example, a file readable only by the owner,
chmod 600) and note the review cadence on it. - Attach that plan as hardening evidence on the asset, naming
SR-2in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.