Supply Chain Operations Security
LOW MODERATE HIGHRequirements NIST SOURCE
Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: [OPSEC controls].
Discussion (NIST Supplemental Guidance)
Supply chain OPSEC expands the scope of OPSEC to include suppliers and potential suppliers. OPSEC is a process that includes identifying critical information, analyzing friendly actions related to operations and other activities to identify actions that can be observed by potential adversaries, determining indicators that potential adversaries might obtain that could be interpreted or pieced together to derive information in sufficient time to cause harm to organizations, implementing safeguards or countermeasures to eliminate or reduce exploitable vulnerabilities and risk to an acceptable level, and considering how aggregated information may expose users or specific uses of the supply chain. Supply chain information includes user identities; uses for systems, system components, and system services; supplier identities; security and privacy requirements; system and component configurations; supplier processes; design specifications; and testing and evaluation results. Supply chain OPSEC may require organizations to withhold mission or business information from suppliers and may include the use of intermediaries to hide the end use or users of systems, system components, or system services.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SR-7 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service are defined;
- <SR-07_ODP OPSEC controls> are employed to protect supply chain-related information for the system, system component, or system service.
Examine
[SELECT FROM: Supply chain risk management plan; supply chain risk management procedures; system and services acquisition policy; system and services acquisition procedures; procedures addressing supply chain protection; list of OPSEC controls to be employed; solicitation documentation; acquisition documentation; acquisition contracts for the system, system component, or system service; records of all-source intelligence analyses; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with acquisition responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel with OPSEC responsibilities; organizational personnel with supply chain risk management responsibilities].
Test
[SELECT FROM: Organizational processes for defining and employing OPSEC safeguards; mechanisms supporting and/or implementing the definition and employment of OPSEC safeguards].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SR-7. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Supply chain risk management plan
- system and services acquisition policy
- system security plan
- privacy plan
Testing
- Organizational processes for defining and employing OPSEC safeguards
- mechanisms supporting and/or implementing the definition and employment of OPSEC safeguards
Other Records
- supply chain risk management procedures
- system and services acquisition procedures
- procedures addressing supply chain protection
- list of OPSEC controls to be employed
- solicitation documentation
- acquisition documentation
- acquisition contracts for the system, system component, or system service
- records of all-source intelligence analyses
- other relevant documents or records