← SR-4

Track and Trace

LOW MODERATE HIGH
0 Overlays 4 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Establish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [systems and critical system components].

Discussion (NIST Supplemental Guidance)

Tracking the unique identification of systems and system components during development and transport activities provides a foundational identity structure for the establishment and maintenance of provenance. For example, system components may be labeled using serial numbers or tagged using radio-frequency identification tags. Labels and tags can help provide better visibility into the provenance of a system or system component. A system or system component may have more than one unique identifier. Identification methods are sufficient to support a forensic investigation after a supply chain compromise or event.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SR-4(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. systems and critical system components that require unique identification for tracking through the supply chain are defined;
  2. the unique identification of <SR-04(02)_ODP systems and critical system components> is established for tracking through the supply chain;
  3. the unique identification of <SR-04(02)_ODP systems and critical system components> is maintained for tracking through the supply chain.

Examine

[SELECT FROM: Supply chain risk management policy and procedures; system and services acquisition policy; procedures addressing supply chain protection; procedures addressing the integration of information security requirements into the acquisition process; supply chain risk management plan; list of supply chain elements, processes, and actors (associated with the system, system component, or system service) requiring implementation of unique identification processes, procedures, tools, mechanisms, equipment, techniques, and/or configurations; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with system and services acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with supply chain protection responsibilities; organizational personnel with responsibilities for establishing and retaining the unique identification of supply chain elements, processes, and actors].

Test

[SELECT FROM: Organizational processes for defining, establishing, and retaining unique identification for supply chain elements, processes, and actors; mechanisms supporting and/or implementing the definition, establishment, and retention of unique identification for supply chain elements, processes, and actors].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SR-4(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Supply chain risk management policy and procedures
  • system and services acquisition policy
  • supply chain risk management plan
  • system security plan

Testing

  • Organizational processes for defining, establishing, and retaining unique identification for supply chain elements, processes, and actors
  • mechanisms supporting and/or implementing the definition, establishment, and retention of unique identification for supply chain elements, processes, and actors

Other Records

  • procedures addressing supply chain protection
  • procedures addressing the integration of information security requirements into the acquisition process
  • list of supply chain elements, processes, and actors (associated with the system, system component, or system service) requiring implementation of unique identification processes, procedures, tools, mechanisms, equipment, techniques, and/or configurations
  • other relevant documents or records