Supply Chain Controls and Processes SR-3
Supply Chain Risk Management · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SR-3 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Supply Chain Risk Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SR-3 (Supply Chain Controls and Processes) requires establishing and documenting processes to manage supply chain risk: identifying and vetting suppliers and components, applying controls against compromised or counterfeit parts, and coordinating those controls across the acquisition lifecycle. It is a Supply Chain Risk Management (SCRM) baseline control.
What good looks like
- Establish and document a process to identify and manage supply chain risks for components and suppliers.
- Vet suppliers and sources, and obtain components only from trusted, authorized channels.
- Apply controls that protect integrity and provenance — signed packages and verification of what you install.
- Coordinate supply chain controls with your other security processes and record them in agreements or plans.
Framework mapping
- NIST CSF 2.0 — GV.SC-01 — A cyber supply chain risk management program, strategy, and processes are established
- CIS Controls v8 — Control 15 — Service Provider Management
How to move it toward Implemented
- The technical provenance pieces exist: packages come from signed, trusted Ubuntu
aptrepositories,unattended-upgradespulls updates from those same trusted sources, and AIDE (Advanced Intrusion Detection Environment) detects tampered files. - The gap is process, not tooling: write a short supply-chain procedure that names the trusted package sources, states how a component is vetted before install, and documents that
aptalready enforces repository GPG (GNU Privacy Guard) signature verification. - Record supplier and source provenance in the component inventory, tying SR-3 to the CM-8 inventory work.
- Attach that procedure naming SR-3 in the Requirement field to move from partial toward Completed; note much of SR-3 is an organizational control that a single VM inherits as a common control.