Track and Trace
LOW MODERATE HIGHRequirements NIST SOURCE
Establish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [systems and critical system components].
Discussion (NIST Supplemental Guidance)
Tracking the unique identification of systems and system components during development and transport activities provides a foundational identity structure for the establishment and maintenance of provenance. For example, system components may be labeled using serial numbers or tagged using radio-frequency identification tags. Labels and tags can help provide better visibility into the provenance of a system or system component. A system or system component may have more than one unique identifier. Identification methods are sufficient to support a forensic investigation after a supply chain compromise or event.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SR-4(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- systems and critical system components that require unique identification for tracking through the supply chain are defined;
- the unique identification of <SR-04(02)_ODP systems and critical system components> is established for tracking through the supply chain;
- the unique identification of <SR-04(02)_ODP systems and critical system components> is maintained for tracking through the supply chain.
Examine
[SELECT FROM: Supply chain risk management policy and procedures; system and services acquisition policy; procedures addressing supply chain protection; procedures addressing the integration of information security requirements into the acquisition process; supply chain risk management plan; list of supply chain elements, processes, and actors (associated with the system, system component, or system service) requiring implementation of unique identification processes, procedures, tools, mechanisms, equipment, techniques, and/or configurations; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with system and services acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with supply chain protection responsibilities; organizational personnel with responsibilities for establishing and retaining the unique identification of supply chain elements, processes, and actors].
Test
[SELECT FROM: Organizational processes for defining, establishing, and retaining unique identification for supply chain elements, processes, and actors; mechanisms supporting and/or implementing the definition, establishment, and retention of unique identification for supply chain elements, processes, and actors].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SR-4(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Supply chain risk management policy and procedures
- system and services acquisition policy
- supply chain risk management plan
- system security plan
Testing
- Organizational processes for defining, establishing, and retaining unique identification for supply chain elements, processes, and actors
- mechanisms supporting and/or implementing the definition, establishment, and retention of unique identification for supply chain elements, processes, and actors
Other Records
- procedures addressing supply chain protection
- procedures addressing the integration of information security requirements into the acquisition process
- list of supply chain elements, processes, and actors (associated with the system, system component, or system service) requiring implementation of unique identification processes, procedures, tools, mechanisms, equipment, techniques, and/or configurations
- other relevant documents or records