← SR-2

Establish SCRM Team

✓ LOW ✓ MODERATE ✓ HIGH
1 Overlay 0 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Establish a supply chain risk management team consisting of [personnel, roles and responsibilities] to lead and support the following SCRM activities: [supply chain risk management activities].

Discussion (NIST Supplemental Guidance)

To implement supply chain risk management plans, organizations establish a coordinated, team-based approach to identify and assess supply chain risks and manage these risks by using programmatic and technical mitigation techniques. The team approach enables organizations to conduct an analysis of their supply chain, communicate with internal and external partners or stakeholders, and gain broad consensus regarding the appropriate resources for SCRM. The SCRM team consists of organizational personnel with diverse roles and responsibilities for leading and supporting SCRM activities, including risk executive, information technology, contracting, information security, privacy, mission or business, legal, supply chain and logistics, acquisition, business continuity, and other relevant functions. Members of the SCRM team are involved in various aspects of the SDLC and, collectively, have an awareness of and provide expertise in acquisition processes, legal practices, vulnerabilities, threats, and attack vectors, as well as an understanding of the technical aspects and dependencies of systems. The SCRM team can be an extension of the security and privacy risk management processes or be included as part of an organizational risk management team.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SR-2(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the personnel, roles, and responsibilities of the supply chain risk management team are defined;
  2. supply chain risk management activities are defined;
  3. a supply chain risk management team consisting of <SR-02(01)_ODP[01] personnel, roles and responsibilities> is established to lead and support <SR-02(01)_ODP[02] supply chain risk management activities>.

Examine

[SELECT FROM: Supply chain risk management policy; supply chain risk management procedures; supply chain risk management team charter documentation; supply chain risk management strategy; supply chain risk management implementation plan; procedures addressing supply chain protection; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with acquisition responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel with supply chain risk management responsibilities; organizational personnel with enterprise risk management responsibilities; legal counsel; organizational personnel with business continuity responsibilities].

Overlays

Showing the OT/ICS overlay for the parent control SR-2 — see the SR-2(1) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)
  • Included: (1)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SR-2(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Supply chain risk management policy
  • supply chain risk management strategy
  • supply chain risk management implementation plan
  • system security plan
  • privacy plan

Other Records

  • supply chain risk management procedures
  • supply chain risk management team charter documentation
  • procedures addressing supply chain protection
  • other relevant documents or records