Validate as Genuine and Not Altered
LOW MODERATE HIGHRequirements NIST SOURCE
Employ the following controls to validate that the system or system component received is genuine and has not been altered: [organization-defined controls].
Discussion (NIST Supplemental Guidance)
For many systems and system components, especially hardware, there are technical means to determine if the items are genuine or have been altered, including optical and nanotechnology tagging, physically unclonable functions, side-channel analysis, cryptographic hash verifications or digital signatures, and visible anti-tamper labels or stickers. Controls can also include monitoring for out of specification performance, which can be an indicator of tampering or counterfeits. Organizations may leverage supplier and contractor processes for validating that a system or component is genuine and has not been altered and for replacing a suspect system or component. Some indications of tampering may be visible and addressable before accepting delivery, such as inconsistent packaging, broken seals, and incorrect labels. When a system or system component is suspected of being altered or counterfeit, the supplier, contractor, or original equipment manufacturer may be able to replace the item or provide a forensic capability to determine the origin of the counterfeit or altered item. Organizations can provide training to personnel on how to identify suspicious system or component deliveries.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SR-4(3) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- controls to validate that the system or system component received is genuine are defined;
- controls to validate that the system or system component received has not been altered are defined;
- <SR-04(03)_ODP[01] controls> are employed to validate that the system or system component received is genuine;
- <SR-04(03)_ODP[02] controls> are employed to validate that the system or system component received has not been altered.
Examine
[SELECT FROM: Supply chain risk management policy and procedures; supply chain risk management plan; system and services acquisition policy; procedures addressing supply chain protection; procedures addressing the security design principle of trusted components used in the specification, design, development, implementation, and modification of the system; system design documentation; procedures addressing the integration of information security requirements into the acquisition process; solicitation documentation; acquisition documentation; service level agreements; acquisition contracts for the system, system component, or system service; evidentiary documentation (including applicable configurations) indicating that the system or system component is genuine and has not been altered; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with system and services acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with supply chain risk management responsibilities].
Test
[SELECT FROM: Organizational processes for defining and employing validation safeguards; mechanisms supporting and/or implementing the definition and employment of validation safeguards; mechanisms supporting the application of the security design principle of trusted components in system specification, design, development, implementation, and modification].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SR-4(3). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Supply chain risk management policy and procedures
- supply chain risk management plan
- system and services acquisition policy
- system security plan
Configuration
- system design documentation
Testing
- Organizational processes for defining and employing validation safeguards
- mechanisms supporting and/or implementing the definition and employment of validation safeguards
- mechanisms supporting the application of the security design principle of trusted components in system specification, design, development, implementation, and modification
Other Records
- procedures addressing supply chain protection
- procedures addressing the security design principle of trusted components used in the specification, design, development, implementation, and modification of the system
- procedures addressing the integration of information security requirements into the acquisition process
- solicitation documentation
- acquisition documentation
- service level agreements
- acquisition contracts for the system, system component, or system service
- evidentiary documentation (including applicable configurations) indicating that the system or system component is genuine and has not been altered
- other relevant documents or records