Supplier Assessments and Reviews SR-6
Supply Chain Risk Management · Moderate baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SR-6 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Supply Chain Risk Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SR-6 (Supplier Assessments and Reviews) asks you to check your suppliers — not just once at signup, but on a regular schedule. You assess the supply chain risk tied to each supplier or contractor and to the specific system, component, or service they provide, then review it again over time. It is a Moderate-baseline control, so it kicks in once a system matters enough to warrant a closer look at who stands behind it.
What good looks like
- Assess each supplier and the exact product or service they give you — not the company in the abstract, but what they actually provide.
- Re-review on a set frequency (for example, yearly) so a supplier that was fine last year does not quietly drift.
- Weigh things like the supplier’s security track record, ownership, and how critical their component is to you.
- Record what you found and any action you took — an assessment with no written result is hard to prove later.
- Feed the results back into buying decisions — a poor review should change what you renew or replace.
Framework mapping
- NIST CSF 2.0 — GV.SC-07 — The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
- CIS Controls v8 — Control 15 — Service Provider Management
How to move it toward Implemented
- List the suppliers behind this server — the operating system vendor, the repositories you pull from, and any third-party software or hardware — and note how critical each one is.
- For each, do a short risk write-up: security reputation, known issues, and your comfort level, with a date.
- Set a review cadence (for example, review annually) and record the next due date so the assessment repeats.
- Attach that supplier assessment as hardening evidence on the asset, naming
SR-6in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.