Component Authenticity
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SR-11 — Component Authenticity. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SR-11 — Component Authenticity. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include CISA.
Enhancements NIST SOURCE
SR-11(1) Anti-counterfeit Training ✓ LOW ✓ MODERATE ✓ HIGH
Train [personnel or roles] to detect counterfeit system components (including hardware, software, and firmware).
Discussion
None.
SR-11(2) Configuration Control for Component Service and Repair ✓ LOW ✓ MODERATE ✓ HIGH
Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [system components].
Discussion
None.
SR-11(3) Anti-counterfeit Scanning LOW MODERATE HIGH
Scan for counterfeit system components [frequency].
Discussion
The type of component determines the type of scanning to be conducted (e.g., web application scanning if the component is a web application).
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SR-11 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- one or more of the following PARAMETER VALUES is/are selected: {source of counterfeit component; <SR-11_ODP[02] external reporting organizations>; <SR-11_ODP[03] personnel or roles>};
- external reporting organizations to whom counterfeit system components are to be reported is/are defined (if selected);
- personnel or roles to whom counterfeit system components are to be reported is/are defined (if selected);
- an anti-counterfeit policy is developed and implemented;
- anti-counterfeit procedures are developed and implemented;
- the anti-counterfeit procedures include the means to detect counterfeit components entering the system;
- the anti-counterfeit procedures include the means to prevent counterfeit components from entering the system;
- counterfeit system components are reported to <SR-11_ODP[01] SELECTED PARAMETER VALUES>.
Examine
[SELECT FROM: Supply chain risk management policy and procedures; supply chain risk management plan; system and services acquisition policy; anti-counterfeit plan; anti-counterfeit policy and procedures; media disposal policy; media protection policy; incident response policy; reports notifying developers, manufacturers, vendors, contractors, and/or external reporting organizations of counterfeit system components; acquisition documentation; service level agreements; acquisition contracts for the system, system component, or system service; inter-organizational agreements and procedures; records of reported counterfeit system components; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with system and service acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with supply chain risk management responsibilities; organizational personnel with responsibilities for anti-counterfeit policies, procedures, and reporting].
Test
[SELECT FROM: Organizational processes for counterfeit prevention, detection, and reporting; mechanisms supporting and/or implementing anti-counterfeit detection, prevention, and reporting].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SR-11. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Supply chain risk management policy and procedures
- supply chain risk management plan
- system and services acquisition policy
- anti-counterfeit plan
- anti-counterfeit policy and procedures
- media disposal policy
- media protection policy
- incident response policy
- system security plan
Testing
- Organizational processes for counterfeit prevention, detection, and reporting
- mechanisms supporting and/or implementing anti-counterfeit detection, prevention, and reporting
Other Records
- reports notifying developers, manufacturers, vendors, contractors, and/or external reporting organizations of counterfeit system components
- acquisition documentation
- service level agreements
- acquisition contracts for the system, system component, or system service
- inter-organizational agreements and procedures
- records of reported counterfeit system components
- other relevant documents or records