Notification Agreements SR-8
Supply Chain Risk Management · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SR-8 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Supply Chain Risk Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SR-8 (Notification Agreements) is about setting up, in advance, the agreements that make suppliers tell you when something goes wrong. You establish agreements and procedures with the entities in your supply chain so that you get notified of a supply chain compromise — and, when you choose, the results of their assessments or audits. It is a Low-baseline control, and it is mostly about paperwork and relationships, not server settings.
What good looks like
- Put notification duties in writing — the supplier agrees to tell you if they are breached or if a component is compromised.
- Decide what you want told to you: at minimum compromises, and optionally the results of the supplier’s own assessments or audits.
- Agree on the how and how-fast — who they contact, by what channel, and within what time.
- Make it specific so a real event triggers a real, timely message, not silence.
- Tie these agreements to your incident response so a supplier’s warning actually reaches the people who act on it.
Framework mapping
- NIST CSF 2.0 — GV.SC-08 — Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
How to move it toward Implemented
- List the suppliers for this server that would need to warn you — the operating system vendor, the repository maintainers, and any paid vendors — and find each one’s security-notification channel (a mailing list, an advisory feed, or a support contact).
- Write down, per supplier, what you expect to be told and how you will receive it (for example, subscribe to the vendor’s security advisory list).
- Note how a received warning flows into your incident-response steps so it does not stop at an inbox.
- Attach that notification-agreement record as hardening evidence on the asset, naming
SR-8in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.