NIST SP 800-161 Rev 1
Evidence request list. 191 controls, 191 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
C-SCRM Family: Access Control
Extends access control policy and procedure to cover suppliers, developers, integrators and service providers, and to be flowed into agreements with them.
- access control policy naming supply chain actors
- contract clauses imposing the policy on suppliers
- review records covering the supply chain sections
- policy silent on non-employee access
- clauses drafted but not present in live contracts
Governs remote access used by suppliers and service providers, which is the ordinary way supply chain access actually happens.
- inventory of supplier remote access paths
- authorization and session records
- monitoring evidence for supplier sessions
- vendor-supplied remote tools installed outside the inventory
- supplier sessions unmonitored
Addresses wireless access introduced or used by suppliers, integrators and delivered equipment.
- authorization records for supplier wireless use
- configuration review of delivered wireless capability
- rogue detection covering supplier areas
- delivered equipment ships with wireless enabled by default
- contractor wireless bridged into the corporate network
Controls supplier and integrator mobile devices that connect to the environment or carry organizational information.
- policy on supplier-owned devices
- register of permitted external devices
- protection requirements imposed by contract
- supplier devices connected with no enrolment or inspection
- organizational data left on devices at contract end
Brings supplier, developer and service provider accounts inside the account lifecycle, including accounts created for maintenance and integration work.
- inventory of supplier and integrator accounts with sponsor
- authorization records for each external account
- evidence of removal at contract end
- accounts persist after the engagement ends
- no internal sponsor named for supplier accounts
Sets the terms under which organizational information may be processed on supplier and provider systems, and verifies them.
- inventory of external systems used by suppliers for organizational data
- agreements setting the security terms
- verification evidence such as assessment or attestation
- supplier subcontracts processing with no notification
- terms agreed but never verified
Governs what supply chain information is shared, with whom, and under what handling conditions.
- sharing decisions with named recipients and conditions
- non-disclosure or handling agreements
- records of shared supply chain information
- sharing decisions made ad hoc by project staff
- conditions imposed but not communicated to the recipient
Prevents supply chain detail that would help an adversary target suppliers or components from reaching public channels.
- review process covering supply chain content before publication
- records of removals
- list of authorized publishers
- supplier names and system detail published in tenders and case studies
- public code repositories exposing dependency detail
Protects supply chain data holdings from mining that would reveal dependencies, volumes or criticality.
- identification of supply chain data stores at aggregation risk
- detection or restriction of bulk extraction
- access limits on procurement and inventory data
- procurement data broadly readable across the organization
- bulk export from supplier portals undetected
Ensures decisions to grant supply chain access are made on defined attributes rather than on the strength of a commercial relationship.
- defined attributes driving external access decisions
- decision records per external party
- periodic revalidation of those decisions
- access granted because the supplier is long-standing
- decisions undocumented so they cannot be revisited
Enforces the boundary between what a supplier or integrator is authorized to reach and the rest of the environment, rather than trusting the relationship.
- entitlement listing per external party
- enforcement configuration limiting external access
- test evidence of an out-of-scope attempt being denied
- supplier access granted at network level rather than to named resources
- enforcement never tested
Controls where supply chain information moves, including data shared with and received from suppliers and integrators.
- documented flows to and from supply chain parties
- enforcement rules implementing those flows
- classification of information shared with suppliers
- supplier file transfer paths outside the flow model
- inbound supplier data trusted without inspection
Separates the duties that would let one party both select or supply a component and approve its acceptance.
- duty separation analysis covering acquisition and acceptance
- role assignments in procurement and receiving
- exception approvals where separation is impractical
- the requester also performs acceptance testing
- supplier staff perform their own acceptance
Holds supplier, developer and integrator privilege to the minimum the engagement needs, for the time it needs it.
- privilege basis per external party
- time-bound or just-in-time access records
- review records for external privilege
- standing administrative access for integrators
- privilege granted for a project retained afterwards
C-SCRM Family: Assessment, Authorization, and Monitoring
Establishes assessment and authorization policy that covers suppliers, delivered components and external service providers.
- policy naming supply chain assessment obligations
- procedures for assessing suppliers and components
- review records
- assessment policy stops at the organizational boundary
Assesses the controls that suppliers and providers operate, rather than accepting a claim that they exist.
- assessment plan covering suppliers in scope
- assessment results or accepted third-party reports
- gap analysis where third-party scope is short
- questionnaire responses accepted as assessment
- third-party report scope never checked against the service used
Governs the connections and exchanges between the organization and its suppliers, integrators and providers.
- inventory of supply chain exchanges and connections
- agreements documenting each
- technical protections and review records
- connections established for a project and never decommissioned
- exchange agreements absent for cloud integrations
Tracks supply chain weaknesses to closure with named owners and dates, including weaknesses residing with a supplier.
- plan of action entries arising from supplier assessments
- owners and dates including supplier-side actions
- closure evidence
- supplier findings recorded but assigned to nobody
- dates slipped repeatedly with no escalation
Makes supply chain risk an explicit input to the decision to authorize a system to operate.
- authorization packages containing supply chain risk information
- decision records referencing supplier and component risk
- conditions imposed relating to the supply chain
- authorization decisions silent on supply chain dependencies
- critical supplier risk never surfaced to the decision maker
Monitors supplier and component risk continuously rather than at the point of purchase or renewal.
- monitoring strategy covering suppliers and critical components
- monitoring output such as supplier risk feeds or reassessments
- evidence results are reviewed and acted on
- supplier reviewed only at renewal
- monitoring feed purchased but unread
C-SCRM Family: Audit and Accountability
Extends audit and accountability policy to cover supply chain events and the logging obligations placed on suppliers.
- audit policy covering supply chain events
- contract clauses requiring supplier logging and access to logs
- review records
- no logging obligation in supplier contracts
Establishes that actions taken by suppliers and integrators, and the provenance claims they make, cannot later be repudiated.
- signing or equivalent mechanism for supplier submissions
- records binding an action to an external party
- verification of supplier signatures
- supplier attestations accepted unsigned
- signatures collected but never verified
Ensures delivered and supplier-operated components actually generate the audit records the organization needs.
- acquisition requirements specifying logging capability
- evidence delivered components log as required
- coverage of supplier-operated components
- appliances delivered with logging that cannot be exported
- supplier-operated components log to the supplier only
Watches external channels for disclosure of organizational or supply chain information, including by suppliers.
- defined channels monitored
- records of disclosures found and actioned
- notification obligations on suppliers
- monitoring covers own brand only, not suppliers
- supplier breach learned from the press
Captures supplier and integrator sessions where the risk warrants observing what was actually done.
- criteria for when session audit applies
- session recordings or transcripts
- access controls on the captured sessions
- session capture available but never enabled for vendor access
- captures retained without access control
Coordinates logging across organizational boundaries so that activity spanning the organization and its suppliers can be reconstructed.
- agreements covering log sharing and retention with suppliers
- evidence of correlated cross-boundary investigation
- time synchronization agreement
- supplier logs unobtainable during an incident
- retention periods incompatible across the boundary
Defines the supply chain events worth logging, such as component receipt, supplier access, and changes made by integrators.
- defined supply chain event types
- logging configuration capturing them
- review of the event list
- supplier activity indistinguishable from internal activity in logs
Requires audit records to identify which supplier, integrator or provider performed an action, not just which account.
- sample records showing external party attribution
- mapping from account to supplier organization
- field configuration
- shared vendor accounts defeat attribution
- supplier organization not recorded anywhere in the log
Reviews supply chain activity in the logs for signs of misuse of supplier access or unexpected change by integrators.
- review procedure including supplier activity
- dated review records
- findings and escalation to supplier management
- review covers internal users only
- findings never raised with the supplier
C-SCRM Family: Awareness and Training
Establishes awareness and training policy that explicitly covers cybersecurity supply chain risk and the people who make acquisition decisions.
- training policy naming C-SCRM as in scope
- identification of roles requiring C-SCRM training
- review records
- training policy covers employees only, not acquisition staff or contractors
Builds general awareness of supply chain threat, including counterfeit components, tampering and supplier compromise.
- awareness content covering supply chain threat
- completion records
- evidence content is refreshed with current threat
- awareness content never mentions supply chain
- acquisition and receiving staff outside the population
Trains the roles that carry C-SCRM duties, including procurement, receiving, engineering and supplier management.
- mapping of C-SCRM roles to required training
- completion records per role
- evidence training precedes the duty
- only the security team receives supply chain training
- procurement staff make risk decisions untrained
Keeps the training record that shows who is competent to carry a C-SCRM duty, including supplier personnel where required by agreement.
- training records reconciled to current role holders
- records for supplier personnel where contractually required
- retention period applied
- records held by the supplier and never obtained
- records not reconciled after reorganization
C-SCRM Family: Configuration Management
Extends configuration management policy to cover components sourced externally and changes made by suppliers and integrators.
- configuration management policy covering supplier change
- contract clauses on change notification
- review records
- supplier changes fall outside the policy entirely
Controls the terms and provenance under which software, including open source, may be used.
- software usage policy including open source terms
- records of licence and provenance per product
- approval route for new software
- open source pulled directly into builds with no approval
- licence terms unknown for inherited software
Prevents users and integrators from installing software of unverified origin onto organizational systems.
- installation restriction configuration
- approved software list
- records of exceptions and their basis
- integrators install tooling on production systems at will
- restriction enforced on endpoints only
Identifies where organizational information sits across the supply chain, including on supplier and provider systems.
- record of information locations including supplier-held copies
- evidence covering subcontracted processing
- update procedure on supplier change
- supplier subcontracting moves data with no notification
- only primary storage identified
Maps the actions taken on organizational data, including by suppliers and processors, so exposure is visible.
- mapping of data actions to systems and parties
- identification of supplier processing actions
- review on change
- supplier processing described only in commercial terms
- mapping never updated after integration changes
Requires and verifies cryptographic signatures on delivered software, firmware and updates before installation.
- signature verification configuration or procedure
- records of verification for sampled updates
- handling of components that cannot be verified
- signatures present but never checked
- unsigned firmware installed because verification is inconvenient
Establishes the baseline for delivered components so that later supplier changes can be detected against a known starting point.
- baseline captured at acceptance for delivered components
- comparison evidence against the supplier-shipped state
- baseline update records after supplier change
- baseline taken after months of operation
- no baseline for appliances and firmware
Brings supplier-initiated and vendor-pushed changes inside change control rather than letting them arrive unannounced.
- change records for supplier-initiated changes
- notification requirements in supplier agreements
- evidence of review before vendor changes are applied
- automatic vendor updates applied with no record
- supplier changes discovered after the fact
Analyses the effect of supplier and component changes before they are accepted, including effects on other dependencies.
- impact analyses for supplier-driven changes
- dependency mapping used in the analysis
- evidence the analysis influenced acceptance
- analysis limited to the changed component
- dependency effects discovered in production
Restricts who, including which supplier personnel, may change components, and records when that right is exercised.
- list of external personnel authorized to make changes
- access configuration enforcing the restriction
- records of supplier-made changes
- supplier holds standing change rights across environments
- no record of which supplier engineer made a change
Sets and verifies secure settings on delivered components rather than accepting the supplier default.
- setting standards applied to delivered component types
- compliance evidence after deployment
- records of default credentials and services changed or disabled
- appliances run on shipped defaults
- supplier forbids configuration change and the risk is unaccepted
Removes supplier-included functionality that the organization does not need and that widens the attack surface.
- review of delivered functionality against need
- records of functions and services disabled
- acquisition requirements limiting bundled functionality
- vendor bundles left enabled because disabling is unsupported
- review performed for software but not firmware
Maintains the component inventory to the depth needed for supply chain purposes, including supplier, origin and support status.
- inventory carrying supplier, origin and support status
- reconciliation to discovery
- procedure for updating on acquisition and disposal
- inventory records model but not supplier or origin
- subcomponents and embedded software invisible
Sets out how configuration will be managed across the organization and its suppliers for the life of the system.
- configuration management plan naming supply chain responsibilities
- roles split between organization and supplier
- plan review records
- plan silent on who manages configuration of supplier-operated components
C-SCRM Family: Contingency Planning
Extends contingency policy to cover the loss of a supplier, provider or component source, not only the loss of a facility.
- contingency policy addressing supplier failure
- procedures for supplier loss scenarios
- review records
- contingency policy assumes the supply chain continues
Provides alternate communications capability where the primary protocol or its supplier becomes unavailable.
- identification of alternate protocols or channels
- test evidence of the alternate working
- dependency analysis on the alternate
- alternate channel depends on the same supplier
- alternate never tested
Plans for continued operation when a critical supplier, integrator or component source becomes unavailable.
- contingency plan with supplier failure scenarios
- identification of critical suppliers and single points of failure
- alternate sourcing arrangements
- plan lists systems but not the suppliers that keep them running
- single-source dependencies unidentified
Trains the people who would have to act if a supplier or component source failed.
- training content covering supplier failure scenarios
- completion records for relevant roles
- evidence of refresh after plan change
- training covers site recovery only
- procurement staff untrained in emergency sourcing
Tests the supply chain elements of the contingency plan, including whether alternate sources can actually deliver.
- test plan including supplier failure scenarios
- test results and lessons
- evidence alternate sources were contacted or validated
- alternate supplier named but never approached
- supply chain scenarios never exercised
Applies supply chain scrutiny to the alternate storage site and the providers that operate it.
- alternate site arrangements and provider identity
- assessment of the alternate provider
- evidence the alternate is not subject to the same supplier dependency
- alternate site run by the same provider as primary
- provider of the alternate never assessed
Applies the same supply chain scrutiny to alternate processing capability and its provider.
- alternate processing arrangements
- assessment of the provider and its own dependencies
- evidence of separation from primary dependencies
- alternate processing depends on the same upstream component source
- capacity commitments unverified
Addresses dependence on telecommunications suppliers, including shared upstream carriers behind nominally separate services.
- service arrangements with named carriers
- analysis of shared upstream infrastructure
- priority service arrangements where applicable
- two circuits from different resellers share one physical path
- upstream carrier unknown
C-SCRM Family: Identification and Authentication
Extends identification and authentication policy to suppliers, integrators, provider staff and non-organizational users.
- policy covering external identities
- procedures for issuing and revoking external credentials
- review records
- external identity handled informally per project
Ensures supplier and integrator personnel working as organizational users are individually identified and strongly authenticated.
- individual accounts for external personnel
- multi-factor configuration for external access
- evidence of no shared vendor accounts
- one shared login per supplier
- exceptions to multi-factor granted to suppliers for convenience
Authenticates devices introduced by suppliers or delivered as part of a component before they are trusted on the network.
- device authentication configuration
- enrolment records for supplier devices
- handling of devices that cannot authenticate
- delivered devices auto-connect on a trusted segment
- supplier laptops exempt from device authentication
Manages identifiers issued to external parties so they are unique, attributable and retired at engagement end.
- identifier assignment records for external parties
- uniqueness and reuse controls
- retirement records at contract end
- identifiers reused across successive contractors
- no link from identifier to supplier organization
Manages authenticators issued to or by suppliers, including default credentials shipped with delivered components.
- issuance and revocation records for external authenticators
- evidence default credentials on delivered components are changed
- protection of authenticators shared with suppliers
- shipped default credentials left in place
- credentials emailed to supplier staff
Handles authentication of supplier and partner users who are not organizational users but still reach organizational systems.
- authentication arrangements for non-organizational users
- federation or trust agreements and their terms
- review of external identity providers
- trust extended to a supplier identity provider with no assessment
- non-organizational users indistinguishable in logs
Authenticates the services and interfaces that supply chain parties expose or consume, not only the people.
- inventory of supplier-facing services and their authentication
- credential and certificate management for those services
- review and rotation records
- service credentials embedded in supplier-supplied code
- machine identities never rotated
C-SCRM Family: Incident Response
Extends incident response policy to cover incidents originating in or affecting the supply chain, and supplier reporting duties.
- incident policy covering supply chain incidents
- contractual notification obligations and timeframes
- review records
- no contractual obligation on suppliers to notify
Trains responders on supply chain incident scenarios such as compromised updates and supplier breach.
- training content covering supply chain incidents
- completion records
- evidence of update as threat changes
- training scenarios cover internal compromise only
Exercises supply chain incident scenarios, including the parts that depend on a supplier responding.
- exercise plans including supply chain scenarios
- results and lessons
- evidence of supplier participation where applicable
- exercises never involve suppliers
- supplier contact details untested until a real incident
Handles incidents that cross the supply chain boundary, where containment depends on a party the organization does not control.
- incident records involving suppliers
- containment actions requiring supplier cooperation
- escalation route into supplier management
- handling stalls waiting for supplier response with no escalation
- supplier told nothing until the incident closes
Tracks supply chain incidents and their status across the organizational boundary.
- tracking records for supply chain incidents
- status updates obtained from suppliers
- aggregate view of supplier incident history
- supplier incidents tracked in email only
- no history so repeat offenders are invisible
Reports supply chain incidents to the parties who need to know, including other users of the same supplier or component.
- reporting thresholds and recipients including external bodies
- records of reports made
- evidence of onward notification where required
- reporting obligations to sector bodies unidentified
- supplier asks for silence and gets it
Secures the response assistance the organization can call on, including from suppliers and providers, before it is needed.
- support arrangements with suppliers for incident response
- contact and escalation details tested for currency
- scope of assistance in agreements
- assistance assumed but not contracted
- contact list stale
Includes supply chain scenarios, supplier roles and notification paths in the incident response plan.
- plan sections covering supply chain incidents
- named supplier roles and contacts
- review and update history
- plan silent on what to do when the compromise arrives through an update
Handles spillage of organizational information into supplier environments, and of supplier information into the organization.
- spillage response procedure covering supplier environments
- records of spillage events and cleanup
- confirmation of removal from supplier systems
- cleanup confirmed by supplier assertion only
- spillage into supplier collaboration tools unrecognised
C-SCRM Family: Maintenance
Extends maintenance policy to cover maintenance performed by suppliers and original equipment manufacturers, on site and remotely.
- maintenance policy covering supplier-performed work
- contract terms on maintenance access and conduct
- review records
- policy assumes maintenance is performed by employees
Controls and records maintenance performed by suppliers, including what was replaced and where the removed part went.
- maintenance records naming the supplier engineer and work performed
- records of parts removed and their disposition
- approval before maintenance begins
- parts removed by the vendor with no record
- maintenance performed without prior approval
Controls the tools and diagnostic media that supplier engineers bring into the environment.
- approved tool list including supplier-supplied tools
- inspection and scanning records for incoming media
- records of tool removal
- vendor laptops connected without inspection
- tools left installed after the visit
Governs remote maintenance performed by suppliers, which is where most supplier technical access actually occurs.
- approval records per remote maintenance session
- authentication and monitoring evidence
- termination of access after the session
- permanent vendor tunnels rather than session enablement
- sessions unmonitored
Authorizes named supplier personnel rather than supplier organizations, and supervises those who are not authorized.
- authorized supplier personnel list by individual
- escort records
- identity verification on arrival
- access granted on the basis of a company badge
- list not updated when supplier staff change
Secures the spares and supplier support needed to restore critical components within the time the organization can tolerate.
- spares holdings or supply agreements for critical components
- support response commitments and their evidence
- criticality analysis driving the requirement
- support commitments assumed rather than contracted
- no spares for components with long lead times
Controls maintenance performed away from the organization's facilities, where custody of the component passes to others.
- field maintenance procedure and authorization
- custody and transport records
- inspection on return
- equipment returned to service without inspection
- custody unrecorded while off site
A control new in this publication: monitors maintenance activity for supply chain risk and shares what is learned with the parties who need it.
- monitoring of maintenance activity for anomaly
- records of information shared about maintenance-related risk
- defined recipients internal and external
- maintenance treated as routine and never monitored
- risk learned during maintenance never shared
C-SCRM Family: Media Protection
Extends media protection policy to media moving to and from suppliers and integrators.
- media policy covering supplier exchange
- procedures for media received from suppliers
- review records
- policy silent on media arriving with delivered equipment
Controls media held on behalf of or received from suppliers until it is sanitized or destroyed.
- register of supplier-related media
- secure storage evidence
- access records
- delivered media stored in general areas
- no register so loss is undetectable
Protects media in transit between the organization and its suppliers and maintains accountability across the handover.
- transport procedure including supplier handovers
- custody and receipt records
- protection applied in transit
- courier used with no manifest of contents
- handover points with no accountability
Sanitizes media before it leaves organizational control, including media returned to suppliers under warranty or lease.
- sanitization procedure covering returns and warranty replacements
- sanitization records with serial numbers
- verification step
- failed drives returned to the vendor unsanitized
- supplier certificate accepted without verification
C-SCRM Family: Personally Identifiable Information Processing and Transparency
Extends personally identifiable information processing and transparency policy to processing performed across the supply chain.
- policy covering third-party processing and transparency
- procedures for provider processing arrangements
- review records
- policy assumes the organization is the only processor
C-SCRM Family: Personnel Security
Extends personnel security policy to the supplier, integrator and provider personnel who work on organizational systems.
- personnel security policy covering external personnel
- contract terms imposing screening and conduct requirements
- review records
- policy applies to employees only
Requires and verifies screening of supplier personnel commensurate with the access they will hold.
- screening requirements by access level in contracts
- verification evidence for supplier personnel
- records of access granted after screening
- supplier asserts screening and it is never verified
- access granted before screening completes
Puts access agreements in place with the individuals from supplier organizations who hold access, not only with their employer.
- signed access agreements from external personnel
- reconciliation to the access list
- renewal on change
- agreement with the supplier company assumed to bind its staff
Sets and enforces the personnel security requirements applying to external providers, including notification when their staff leave.
- requirements imposed on providers
- notification obligations for personnel change and their evidence
- records of access removed on notification
- provider does not notify departures so access lingers
- requirements set but compliance never checked
C-SCRM Family: Physical and Environmental Protection
Extends physical protection policy to supplier access, deliveries and the physical points where the supply chain meets the organization.
- physical security policy covering deliveries and supplier access
- procedures for the receiving area
- review records
- policy covers staff access only
Controls what components enter and leave the facility and records their movement, which is the physical control point for counterfeit and tamper risk.
- delivery and removal records
- authorization for removals
- inspection at the point of delivery
- deliveries accepted with no inspection or record
- removals unauthorized and untracked
Applies supply chain and physical protection expectations to alternate work sites used by contractors and supplier staff.
- defined requirements for alternate sites
- assessment or attestation evidence
- agreements with the parties working there
- contractor home sites outside any requirement
- requirements defined but never assessed
Considers where components are physically placed, including whether supplier-managed equipment sits where it can be reached or observed.
- placement rationale for critical components
- assessment of physical exposure including supplier-managed equipment
- records of relocation decisions
- supplier equipment placed in shared or public areas
- placement decided by convenience only
Authorizes supplier and delivery personnel individually and keeps that authorization current.
- authorized supplier personnel list
- credential issue and return records
- review records
- supplier badges issued and never returned
- authorization by company rather than individual
Tracks components physically through receipt, deployment and disposal so that substitution or diversion is detectable.
- tracking method and its coverage
- movement records from receipt to disposal
- reconciliation between tracking and inventory
- tracking stops once the asset is deployed
- reconciliation never performed
Considers supply chain and threat factors in the choice of facility location, including dependence on local infrastructure and providers.
- siting analysis including supply chain and infrastructure factors
- records of the decision and its basis
- reassessment on significant change
- siting decided on cost alone
- local single-provider dependencies unexamined
Controls physical access at the points where components and suppliers enter, including loading docks and receiving areas.
- access control at delivery and receiving points
- escort arrangements for supplier personnel
- records of access to component storage
- receiving area open to anyone with a delivery
- components staged in unsecured areas before acceptance
Monitors physical access at supply chain touch points and reviews what the monitoring shows.
- monitoring coverage of receiving, storage and staging areas
- review records
- incident records and responses
- cameras present but no review
- monitoring stops at the office and excludes the warehouse
C-SCRM Family: Planning
Extends planning policy so that supply chain considerations enter system planning rather than arriving at procurement.
- planning policy referencing supply chain
- procedures embedding C-SCRM in planning
- review records
- supply chain first considered at purchase order stage
Selects the control baseline with supply chain risk taken into account, so C-SCRM controls are chosen rather than assumed.
- baseline selection record including C-SCRM control choices
- rationale for inclusion or exclusion
- approval of the selected baseline
- C-SCRM controls dropped in tailoring with no rationale
- baseline selected before criticality is understood
Records the supply chain dependencies, suppliers and C-SCRM controls of a system in its security plan.
- security plan sections covering supply chain dependencies
- identification of critical suppliers and components
- plan review and update records
- plan lists controls but not the suppliers who operate them
- dependencies unrecorded so nobody can assess concentration
Sets the behavioural expectations that apply to supplier, integrator and provider personnel using organizational systems.
- rules applying to external personnel
- acknowledgement records for supplier staff
- reissue after change
- rules acknowledged by employees only
- supplier staff never see the rules
Describes how the system will actually be operated, including which parts suppliers and providers operate and the boundaries between them.
- concept of operations naming operational responsibilities
- split of duties between organization and providers
- review on change
- operating model undocumented so responsibility gaps appear during incidents
Builds supply chain considerations into architecture, including diversity, provenance and the ability to replace a supplier.
- architecture artefacts addressing supplier dependency and diversity
- analysis of substitutability for critical components
- architecture decision records
- architecture locks the organization to a single supplier with no analysis
- diversity considered for hardware but not software dependencies
Centrally manages the C-SCRM controls that should be consistent across the organization rather than reinvented per project.
- list of centrally managed C-SCRM controls
- evidence of consistent application
- governance over changes to those controls
- each business unit runs its own supplier assessment with different standards
C-SCRM Family: Program Management
Ensures the authorization process carries supply chain risk information to the person making the decision.
- authorization process description including C-SCRM inputs
- evidence supply chain risk reached the decision maker
- conditions imposed relating to suppliers
- authorization packages omit supplier risk entirely
Defines mission and business processes in a way that exposes which supply chain elements they actually depend on.
- process definitions with their supply chain dependencies
- criticality attached to those dependencies
- review on process change
- processes documented without naming the suppliers that enable them
Extends the insider threat programme to insiders introduced through the supply chain, including contractor and integrator personnel.
- programme scope covering supplier personnel
- legal and privacy basis for that scope
- referral and case records
- programme covers employees only while integrators hold deeper access
Builds the workforce capability needed to do C-SCRM work, including acquisition and supplier management skills.
- capability requirements for C-SCRM roles
- development and recruitment plans
- competence records
- supplier risk assessed by staff with no training in it
Plans and coordinates testing, training and monitoring so that C-SCRM activities are scheduled rather than incidental.
- integrated schedule of C-SCRM testing, training and monitoring
- evidence activities occurred as scheduled
- adjustment records
- activities happen only in response to an incident
Maintains contact with external groups that share supply chain threat and vulnerability information.
- memberships and participation records
- information received and how it was used
- internal distribution of what is learned
- membership held but never used
- information received and never distributed
Maintains awareness of threat actors targeting the supply chain and feeds that awareness into decisions.
- threat awareness sources and products
- evidence supply chain threat informs supplier decisions
- distribution to acquisition and engineering
- threat awareness stops at the security team
Sets and enforces the terms under which external parties may hold controlled unclassified information.
- identification of external systems holding such information
- contract terms imposing protection requirements
- verification of compliance
- requirements flowed down but never verified
- holdings unidentified so terms are unenforceable
Includes supply chain processing in the privacy programme plan, since much personal data is handled by providers.
- privacy programme plan covering supplier processing
- inventory of processors
- oversight arrangements
- privacy plan assumes processing is internal
Names the leader accountable for privacy including the privacy risk carried by the supply chain.
- appointment and authority record
- reporting line
- evidence of involvement in supplier decisions
- privacy leader unaware of processors engaged by business units
Places accountability for the cybersecurity supply chain programme with a named leader who has the authority to act on it.
- appointment record naming the accountable leader
- statement of authority and budget
- reporting line to executive level
- accountability spread across procurement and security with no single owner
Makes clear to individuals how their information is handled, including by suppliers and providers acting for the organization.
- published privacy information covering third-party processing
- review of accuracy against actual processors
- update process
- notice silent on providers that hold the data
Accounts for disclosures made to and through supply chain parties.
- disclosure records including transfers to providers
- retention of the accounting
- process for responding to requests
- transfers to processors not treated as disclosures
Maintains data quality across the supply chain, where data passes through providers who may alter or degrade it.
- quality requirements imposed on processors
- quality checks on data returned from providers
- correction process spanning the chain
- quality assumed for data processed externally
- corrections not propagated to providers
Gives the data governance body oversight of data that moves into and through the supply chain.
- governance body terms of reference covering third-party data
- decision records on supplier data arrangements
- membership including procurement and privacy
- governance body never sees supplier data arrangements
Prevents real personal data being handed to suppliers and developers for testing, training or research.
- policy prohibiting production data in test environments
- technical controls or masking evidence
- records of approved exceptions
- production data copied to supplier test environments as routine
- masking applied inconsistently
Handles complaints that arise from supply chain handling of information and routes them to the responsible party.
- complaint process covering third-party handling
- records of complaints and outcomes
- escalation route to suppliers
- complaints about a provider have nowhere to go
Reports on privacy including the risk and incidents arising from the supply chain.
- privacy reports covering third-party processing
- recipients and frequency
- evidence reports drive action
- reporting covers internal processing only
Frames supply chain risk explicitly: the assumptions, constraints, tolerances and priorities that govern how it is judged.
- risk framing statement covering supply chain
- recorded assumptions and constraints
- review of the framing
- framing implicit so different teams judge supplier risk differently
Names the leadership roles that own supply chain risk and distinguishes them from those who own the systems.
- defined risk leadership roles including C-SCRM
- appointment records
- authority and escalation paths
- roles named in policy but unfilled
Funds C-SCRM as a line of work rather than expecting it from existing capacity.
- budget lines covering C-SCRM activity
- staffing allocated to supplier assessment and monitoring
- evidence resource requests are considered in planning
- C-SCRM assigned with no resource so it happens only after an incident
Sets the organizational C-SCRM strategy and implementation plan that everything else in the programme derives from.
- C-SCRM strategy with objectives and scope
- implementation plan with owners and milestones
- review and update records
- approval at executive level
- strategy written once and never operationalized
- no implementation plan behind the strategy
Defines what supply chain risk is monitored continuously, how often, and what triggers action.
- monitoring strategy naming supply chain metrics and frequencies
- defined thresholds and triggers
- evidence of monitoring output and response
- monitoring strategy lists tools rather than what is being watched
Ensures systems and components are used only for the purpose they were acquired and assessed for, since repurposing invalidates the supply chain assessment.
- records of intended purpose per system or component
- approval process for repurposing
- reassessment evidence when purpose changes
- components repurposed into higher-criticality use with no reassessment
Runs a process that carries supply chain weaknesses through to closure at organizational level, not only per system.
- organization-level plan of action including supply chain items
- process for escalation and closure
- aggregate reporting on open items
- supply chain findings tracked per project and never aggregated
Maintains the organizational system inventory in a form that supports supply chain questions such as which systems depend on a given supplier.
- system inventory linked to suppliers and critical components
- query evidence answering supplier exposure questions
- update procedure
- inventory cannot answer which systems a compromised supplier touches
Measures whether the C-SCRM programme is actually reducing risk rather than producing activity.
- defined C-SCRM measures and their definitions
- reported values over time
- evidence measures inform decisions
- measures count assessments completed rather than risk reduced
Reflects supply chain dependency and concentration in the enterprise architecture so that structural risk is visible.
- architecture views showing supplier and component dependency
- concentration analysis
- use of the architecture in investment decisions
- architecture models technology but not who supplies it
Addresses supply chain dependency in the critical infrastructure plan, including upstream providers the organization does not contract with directly.
- critical infrastructure plan naming supply chain dependencies
- analysis of upstream and sub-tier dependency
- coordination arrangements
- plan covers own assets only
- sub-tier dependencies unmapped
Sets how supply chain risk is framed, assessed, responded to and monitored as part of the organizational risk strategy.
- risk management strategy including supply chain
- risk appetite or tolerance statements covering supplier risk
- evidence of integration with enterprise risk
- supply chain risk run separately from enterprise risk with no aggregation
C-SCRM Family: Risk Assessment
Extends risk assessment policy so that supply chain risk is assessed as a class of risk in its own right.
- risk assessment policy naming supply chain risk
- assessment procedures for suppliers and components
- review records
- supply chain risk folded into vendor management with no security assessment
Hunts for adversary activity introduced through the supply chain rather than waiting for an alert.
- hunt plans including supply chain hypotheses
- hunt records and findings
- use of supplier and component intelligence in hunts
- hunting focuses on perimeter intrusion only
- supplier compromise indicators never hunted for
Categorizes systems in a way that carries through to the criticality of the components and suppliers they depend on.
- categorization records
- linkage from system category to component and supplier criticality
- review on change
- categorization stops at the system and never reaches its dependencies
Assesses supply chain risk across the enterprise, mission and system levels, and keeps it current.
- supply chain risk assessments at each level
- methodology covering supplier, component and process risk
- update evidence on change
- risk register entries with owners
- one assessment covering all suppliers equally
- assessment never repeated after supplier change
Monitors vulnerabilities in acquired and third-party components, including dependencies the organization did not choose directly.
- coverage of acquired and open source components
- dependency or bill of materials data driving the monitoring
- remediation records including supplier-dependent fixes
- scanning covers deployed systems but not embedded dependencies
- fixes blocked on the supplier with no tracking
Responds to supply chain risk with decisions that are recorded, owned and revisited, including decisions to accept.
- response decisions per supply chain risk
- approver at the appropriate level
- tracking of mitigations to closure
- acceptance by default because no alternative supplier was sought
Identifies which components and suppliers actually matter, so that C-SCRM effort concentrates where failure would hurt.
- criticality analysis method and results
- identification of critical components and single points of failure
- use of the results to prioritize controls
- review on change
- every supplier treated as equally critical so nothing is prioritized
- analysis performed once and never revisited
C-SCRM Family: Supply Chain Risk Management
Establishes the supply chain risk management policy and procedures that the rest of the SR family operates under.
- C-SCRM policy with approval and scope
- procedures implementing it
- named roles and responsibilities
- review and update records
- policy exists with no procedures behind it
- policy owner unnamed
Inspects systems and components at defined points to detect tampering, substitution or counterfeit.
- inspection procedure and the points at which it applies
- inspection records with results
- criteria for what constitutes a failed inspection
- escalation for failed inspections
- inspection performed only when something looks wrong
- inspection criteria undefined so results are subjective
Establishes an anti-counterfeit policy and the means to detect and report counterfeit components.
- anti-counterfeit policy and procedures
- authenticity verification methods used
- records of suspected counterfeits and their reporting
- training for staff who receive components
- authenticity assumed because the reseller is authorized
- suspected counterfeits discarded rather than reported
Disposes of components so that organizational information and the components themselves cannot re-enter the supply chain uncontrolled.
- disposal procedure covering data and physical component
- disposal records with serial numbers
- controls preventing resale of components carrying organizational identity
- third-party disposal supplier assessment
- components sold on with organizational markings intact
- disposal supplier unassessed
A control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.
- supplier inventory with the systems and components each supports
- criticality attached to each supplier
- update procedure on supplier change
- sub-tier supplier information where obtainable
- supplier list held by procurement with no link to systems
- sub-tier suppliers entirely unknown
- inventory cannot answer which systems a given supplier touches
Requires a plan for managing supply chain risk for the system, reviewed and updated and protected from disclosure.
- system-level C-SCRM plan
- review and update records
- protection and access control on the plan
- linkage to the risk register
- one generic plan reused for every system
- plan never updated after supplier change
Establishes the processes that identify and address supply chain risk for the system, in coordination with its suppliers.
- defined supply chain processes for the system
- evidence of coordination with suppliers
- records of risks identified and addressed
- flow down to sub-tier where required
- processes defined centrally and unused by the projects
- sub-tier suppliers outside every process
Establishes and maintains provenance for systems, components and associated data so origin and change history are known.
- provenance records for critical components
- evidence of origin and chain of custody
- update of provenance as components change
- bill of materials where available
- provenance known only as far as the reseller
- provenance captured at purchase and never maintained
Uses acquisition strategy, contract tools and purchasing methods to reduce supply chain risk before it enters the organization.
- acquisition strategies differentiated by criticality
- contract tools and clauses in use
- evidence of application in real purchases
- supplier selection criteria including security
- one purchasing approach for critical and trivial alike
- clauses available but rarely used
Assesses and reviews suppliers, at a depth matched to what they supply and the access they hold.
- assessment methodology and tiering by criticality
- assessment records per supplier
- review cycle evidence
- findings and their treatment
- all suppliers assessed with the same questionnaire
- assessment at onboarding only
Applies operations security to acquisition so that adversaries cannot learn what is being bought, from whom and when.
- operations security measures applied to acquisition
- controls on disclosure of supplier and delivery detail
- awareness for procurement staff
- delivery schedules and destinations broadly visible
- supplier relationships publicised in detail
Establishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.
- notification clauses with defined triggers and timeframes
- evidence of notifications received
- escalation route when notification fails
- coverage of sub-tier events
- notification obligation absent or without a timeframe
- notifications received and not routed anywhere
Applies tamper resistance and detection to components across development, transport and operation.
- tamper resistance and detection measures in use
- inspection procedures and records
- handling of components found tampered with
- tamper evidence applied but never inspected on receipt
- no procedure for a component that fails inspection
C-SCRM Family: System and Communications Protection
Extends system and communications protection policy to the connections and components that the supply chain introduces.
- policy covering supplier connections and delivered components
- procedures for protecting those connections
- review records
- policy silent on supplier connectivity
Controls mobile code that arrives with delivered components or from supplier-hosted content.
- permitted mobile code definition
- controls on supplier-hosted content and embedded code
- monitoring or blocking evidence
- supplier portals require permissive browser settings
- embedded code in delivered products unexamined
Favours platform independence so that dependency on a single supplier's platform does not become structural.
- portability requirements in acquisition
- analysis of platform dependency for critical applications
- migration feasibility assessments
- applications bound to one supplier platform with no exit analysis
Protects organizational information at rest wherever it sits, including on supplier and provider systems.
- identification of at-rest locations including provider systems
- protection applied and evidence of it
- key management arrangements where the provider holds keys
- provider holds both data and keys with no analysis of that concentration
- backups at providers unprotected
Uses diversity of components and suppliers so a single compromised source cannot affect everything at once.
- analysis of component and supplier concentration
- diversity decisions and their rationale
- identification of common-mode dependencies
- standardization pursued to the point of a single point of failure
- diversity claimed while all products share one upstream component
Uses concealment and misdirection so that supply chain and system detail useful to an adversary is not freely observable.
- assessment of what supply chain detail is externally observable
- concealment measures applied
- review of public and partner-facing disclosure
- detailed technology and supplier stack published in marketing material
Distributes processing and storage so that the failure or compromise of one supplier or site does not take everything with it.
- distribution design and rationale
- analysis of shared dependencies across the distributed set
- test evidence of operation with one part unavailable
- distributed sites all served by the same provider
- distribution designed for capacity rather than resilience
Maintains out-of-band channels for the information and credentials that must not travel the same path as the thing they protect.
- identification of information requiring out-of-band handling
- channel arrangements including with suppliers
- evidence of use
- verification data sent by the same channel as the delivery it verifies
- out-of-band channel provided by the same supplier
Applies operations security so that supply chain activity does not reveal capability, dependency or timing to an adversary.
- operations security assessment covering acquisition activity
- controls on disclosure in tenders and procurement
- training for staff involved
- tender documents reveal architecture and dependencies publicly
Prevents information leaking through resources shared with suppliers, providers or other tenants.
- identification of resources shared with external parties
- controls preventing residual data exposure
- evidence for multi-tenant provider platforms
- multi-tenant provider assumed safe with no evidence
- shared development environments hold production data
Provides alternative communications paths that do not share the same supplier or physical route as the primary.
- identification of primary and alternate paths and their suppliers
- analysis of shared physical route or upstream carrier
- test evidence
- alternate path shares the same duct or upstream carrier
- alternate never exercised
Addresses denial of service risk that arrives through or depends on supply chain parties.
- protection arrangements and where they are provided from
- dependency analysis on the protecting provider
- test or exercise evidence
- protection provided by the same party whose failure is the risk
- no arrangement for provider-side outage
Controls and monitors the boundaries where supplier, integrator and provider connections meet the organization.
- identification of supply chain boundaries and connections
- boundary device rule sets for those connections
- monitoring evidence
- review of the connection inventory
- supplier connections terminate inside the trusted network
- connections accumulate with no review
Protects information in transit between the organization and its suppliers, providers and integrators.
- inventory of supply chain transmission paths and their protection
- cipher and protocol configuration
- evidence weak protocols are disabled on those paths
- supplier file transfer over unprotected channels
- protection assumed because the link is private
C-SCRM Family: System and Information Integrity
Extends system and information integrity policy to cover integrity of components and updates arriving from the supply chain.
- integrity policy covering delivered components and updates
- procedures for verifying what arrives
- review records
- policy addresses running systems but not what is installed onto them
Manages retention and disposal of information across the supply chain, including information held by providers after the engagement.
- retention requirements imposed on providers
- evidence of disposal at engagement end
- identification of provider-held information
- provider retains data indefinitely after contract end
- disposal asserted with no confirmation
Remediates flaws in acquired components, where the fix depends on a supplier the organization does not control.
- patch process covering acquired and embedded components
- tracking of fixes pending with suppliers
- compensating controls where no fix is available
- escalation route to suppliers
- flaws in supplier products tracked nowhere because the fix is not ours
- no compensating control while waiting for a supplier fix
Uses tainting techniques so that unauthorized exfiltration of organizational information through the supply chain can be detected.
- tainting approach and where it is applied
- detection arrangements
- records of any detections and response
- technique described but never deployed
- no detection route for tainted data if it surfaces
Protects against malicious code introduced through delivered components, updates and supplier channels.
- scanning of incoming components, media and updates
- protection coverage on supplier-connected systems
- records of detections in the delivery path
- updates trusted because they came from the vendor
- incoming media scanned only when convenient
Monitors for behaviour indicating compromise arriving through the supply chain, such as unexpected outbound activity from delivered components.
- monitoring coverage of delivered and supplier-operated components
- detection use cases for supply chain compromise
- alert records and triage
- delivered appliances excluded from monitoring
- outbound connections from vendor equipment unexamined
Receives and acts on advisories concerning acquired components and the suppliers behind them.
- named sources covering acquired components
- records of advisories received and actioned
- supplier notification obligations
- advisory sources cover the operating system but not the appliances and libraries in use
Verifies the integrity of software and firmware received from suppliers, before and after installation.
- integrity verification method and evidence for received software and firmware
- baseline hashes or signatures retained
- periodic re-verification records
- integrity checked at install and never again
- firmware integrity unverifiable and the risk unaccepted
C-SCRM Family: System and Services Acquisition
Extends system and services acquisition policy so that security and supply chain requirements enter acquisition from the start.
- acquisition policy including security and C-SCRM requirements
- procedures for supplier selection and contracting
- review records
- security requirements added after supplier selection
Requires the developer or supplier to manage configuration of what they deliver, and to prove it.
- developer configuration management requirements in contract
- evidence of the developer's configuration management such as version and change records
- integrity verification of delivered items
- delivered builds not reproducible
- developer change records unavailable to the organization
Requires developers and suppliers to test what they deliver and to make the results available.
- testing requirements in contract
- developer test plans and results received
- evidence of flaw remediation by the developer
- independent verification where warranted
- test results asserted in a summary letter with no detail
- flaws found by the developer never disclosed
Sets expectations on the developer's own process, standards and tooling, since delivered security depends on them.
- required development standards in contract
- evidence of the developer's process and tool use
- review of the developer's own supply chain for tooling
- process requirements unverified
- developer tool chain never considered as a risk
Obtains the training needed to operate and secure delivered components correctly.
- training requirements in contract
- delivery records
- evidence knowledge transferred to the operating team
- training delivered to a project team that then disbands
- no training obtained for security-relevant features
Requires the developer to produce architecture and design evidence sufficient for the organization to judge the security of what it is buying.
- architecture and design deliverables required and received
- review records of those deliverables
- traceability from requirement to design
- design evidence withheld as proprietary and the risk unaccepted
- deliverables received but never reviewed
Allocates the resources needed to meet supply chain security requirements as part of the acquisition, not as an afterthought.
- resource allocation records within acquisitions
- evidence C-SCRM cost is included in business cases
- approval records
- supply chain assurance unfunded so it does not happen
Considers building or customizing critical components where the market cannot supply them at the assurance level required.
- identification of components where market supply is inadequate
- decision records on custom development
- assurance arrangements for custom components
- critical dependency on a component nobody has assessed and no alternative considered
Requires screening of the developer personnel who will have access to what matters, and verifies it.
- screening requirements in contract by access level
- verification evidence
- records of personnel covered
- screening asserted by the developer and never verified
- subcontracted developers outside the requirement
Manages components the supplier no longer supports, which is where supply chain risk quietly accumulates.
- inventory with support status and end-of-support dates
- replacement plans and funding
- approvals and mitigations for continued use
- alternative support arrangements where used
- support status untracked until a vulnerability is published
- continued use with no approval or compensating control
Runs C-SCRM activities at defined points across the development life cycle, including for acquired components.
- life cycle definition with C-SCRM activities and gates
- evidence activities occurred at those points
- roles assigned across the life cycle
- C-SCRM activity concentrated at purchase with nothing during development or disposal
Puts security and supply chain requirements into the contract, including the evidence the supplier must provide.
- contract templates carrying security and C-SCRM requirements
- evidence of requirements in executed contracts
- acceptance criteria tied to those requirements
- supplier deliverables such as documentation and bills of materials
- requirements in the template but absent from signed contracts
- no acceptance criteria so requirements are unenforceable
Obtains and retains the documentation needed to operate, secure and assess acquired components over their life.
- documentation received per acquisition
- retention and access arrangements
- records where documentation was refused and what was done
- documentation promised but never delivered
- documentation held by a departed integrator
Applies engineering principles to acquired and integrated components, not only to what is built in house.
- engineering principles adopted
- evidence of application in integration design
- review records for acquired component integration
- principles applied to in-house build while integrations bypass them
Governs external service providers across their life cycle, including the security roles each party holds.
- inventory of external services
- agreements defining security roles and responsibilities
- monitoring and assessment evidence
- exit and transition arrangements
- responsibilities assumed rather than defined
- no exit plan so provider change is impossible
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-161 Rev 1 framework page.