Skip to content

Evidence request lists

NIST SP 800-161 Rev 1

Evidence request list. 191 controls, 191 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

C-SCRM Family: Access Control

161R1-AC-1
Policy and Procedures

Extends access control policy and procedure to cover suppliers, developers, integrators and service providers, and to be flowed into agreements with them.

Artefacts an auditor will ask for
  • access control policy naming supply chain actors
  • contract clauses imposing the policy on suppliers
  • review records covering the supply chain sections
Where this commonly fails
  • policy silent on non-employee access
  • clauses drafted but not present in live contracts
161R1-AC-17
Remote Access

Governs remote access used by suppliers and service providers, which is the ordinary way supply chain access actually happens.

Artefacts an auditor will ask for
  • inventory of supplier remote access paths
  • authorization and session records
  • monitoring evidence for supplier sessions
Where this commonly fails
  • vendor-supplied remote tools installed outside the inventory
  • supplier sessions unmonitored
161R1-AC-18
Wireless Access

Addresses wireless access introduced or used by suppliers, integrators and delivered equipment.

Artefacts an auditor will ask for
  • authorization records for supplier wireless use
  • configuration review of delivered wireless capability
  • rogue detection covering supplier areas
Where this commonly fails
  • delivered equipment ships with wireless enabled by default
  • contractor wireless bridged into the corporate network
161R1-AC-19
Access Control for Mobile Devices

Controls supplier and integrator mobile devices that connect to the environment or carry organizational information.

Artefacts an auditor will ask for
  • policy on supplier-owned devices
  • register of permitted external devices
  • protection requirements imposed by contract
Where this commonly fails
  • supplier devices connected with no enrolment or inspection
  • organizational data left on devices at contract end
161R1-AC-2
Account Management

Brings supplier, developer and service provider accounts inside the account lifecycle, including accounts created for maintenance and integration work.

Artefacts an auditor will ask for
  • inventory of supplier and integrator accounts with sponsor
  • authorization records for each external account
  • evidence of removal at contract end
Where this commonly fails
  • accounts persist after the engagement ends
  • no internal sponsor named for supplier accounts
161R1-AC-20
Use of External Systems

Sets the terms under which organizational information may be processed on supplier and provider systems, and verifies them.

Artefacts an auditor will ask for
  • inventory of external systems used by suppliers for organizational data
  • agreements setting the security terms
  • verification evidence such as assessment or attestation
Where this commonly fails
  • supplier subcontracts processing with no notification
  • terms agreed but never verified
161R1-AC-21
Information Sharing

Governs what supply chain information is shared, with whom, and under what handling conditions.

Artefacts an auditor will ask for
  • sharing decisions with named recipients and conditions
  • non-disclosure or handling agreements
  • records of shared supply chain information
Where this commonly fails
  • sharing decisions made ad hoc by project staff
  • conditions imposed but not communicated to the recipient
161R1-AC-22
Publicly Accessible Content

Prevents supply chain detail that would help an adversary target suppliers or components from reaching public channels.

Artefacts an auditor will ask for
  • review process covering supply chain content before publication
  • records of removals
  • list of authorized publishers
Where this commonly fails
  • supplier names and system detail published in tenders and case studies
  • public code repositories exposing dependency detail
161R1-AC-23
Data Mining Protection

Protects supply chain data holdings from mining that would reveal dependencies, volumes or criticality.

Artefacts an auditor will ask for
  • identification of supply chain data stores at aggregation risk
  • detection or restriction of bulk extraction
  • access limits on procurement and inventory data
Where this commonly fails
  • procurement data broadly readable across the organization
  • bulk export from supplier portals undetected
161R1-AC-24
Access Control Decisions

Ensures decisions to grant supply chain access are made on defined attributes rather than on the strength of a commercial relationship.

Artefacts an auditor will ask for
  • defined attributes driving external access decisions
  • decision records per external party
  • periodic revalidation of those decisions
Where this commonly fails
  • access granted because the supplier is long-standing
  • decisions undocumented so they cannot be revisited
161R1-AC-3
Access Enforcement

Enforces the boundary between what a supplier or integrator is authorized to reach and the rest of the environment, rather than trusting the relationship.

Artefacts an auditor will ask for
  • entitlement listing per external party
  • enforcement configuration limiting external access
  • test evidence of an out-of-scope attempt being denied
Where this commonly fails
  • supplier access granted at network level rather than to named resources
  • enforcement never tested
161R1-AC-4
Information Flow Enforcement

Controls where supply chain information moves, including data shared with and received from suppliers and integrators.

Artefacts an auditor will ask for
  • documented flows to and from supply chain parties
  • enforcement rules implementing those flows
  • classification of information shared with suppliers
Where this commonly fails
  • supplier file transfer paths outside the flow model
  • inbound supplier data trusted without inspection
161R1-AC-5
Separation of Duties

Separates the duties that would let one party both select or supply a component and approve its acceptance.

Artefacts an auditor will ask for
  • duty separation analysis covering acquisition and acceptance
  • role assignments in procurement and receiving
  • exception approvals where separation is impractical
Where this commonly fails
  • the requester also performs acceptance testing
  • supplier staff perform their own acceptance
161R1-AC-6
Least Privilege

Holds supplier, developer and integrator privilege to the minimum the engagement needs, for the time it needs it.

Artefacts an auditor will ask for
  • privilege basis per external party
  • time-bound or just-in-time access records
  • review records for external privilege
Where this commonly fails
  • standing administrative access for integrators
  • privilege granted for a project retained afterwards

C-SCRM Family: Assessment, Authorization, and Monitoring

161R1-CA-1
Policy and Procedures

Establishes assessment and authorization policy that covers suppliers, delivered components and external service providers.

Artefacts an auditor will ask for
  • policy naming supply chain assessment obligations
  • procedures for assessing suppliers and components
  • review records
Where this commonly fails
  • assessment policy stops at the organizational boundary
161R1-CA-2
Control Assessments

Assesses the controls that suppliers and providers operate, rather than accepting a claim that they exist.

Artefacts an auditor will ask for
  • assessment plan covering suppliers in scope
  • assessment results or accepted third-party reports
  • gap analysis where third-party scope is short
Where this commonly fails
  • questionnaire responses accepted as assessment
  • third-party report scope never checked against the service used
161R1-CA-3
Information Exchange

Governs the connections and exchanges between the organization and its suppliers, integrators and providers.

Artefacts an auditor will ask for
  • inventory of supply chain exchanges and connections
  • agreements documenting each
  • technical protections and review records
Where this commonly fails
  • connections established for a project and never decommissioned
  • exchange agreements absent for cloud integrations
161R1-CA-5
Plan of Action and Milestones

Tracks supply chain weaknesses to closure with named owners and dates, including weaknesses residing with a supplier.

Artefacts an auditor will ask for
  • plan of action entries arising from supplier assessments
  • owners and dates including supplier-side actions
  • closure evidence
Where this commonly fails
  • supplier findings recorded but assigned to nobody
  • dates slipped repeatedly with no escalation
161R1-CA-6
Authorization

Makes supply chain risk an explicit input to the decision to authorize a system to operate.

Artefacts an auditor will ask for
  • authorization packages containing supply chain risk information
  • decision records referencing supplier and component risk
  • conditions imposed relating to the supply chain
Where this commonly fails
  • authorization decisions silent on supply chain dependencies
  • critical supplier risk never surfaced to the decision maker
161R1-CA-7
Continuous Monitoring

Monitors supplier and component risk continuously rather than at the point of purchase or renewal.

Artefacts an auditor will ask for
  • monitoring strategy covering suppliers and critical components
  • monitoring output such as supplier risk feeds or reassessments
  • evidence results are reviewed and acted on
Where this commonly fails
  • supplier reviewed only at renewal
  • monitoring feed purchased but unread

C-SCRM Family: Audit and Accountability

161R1-AU-1
Policy and Procedures

Extends audit and accountability policy to cover supply chain events and the logging obligations placed on suppliers.

Artefacts an auditor will ask for
  • audit policy covering supply chain events
  • contract clauses requiring supplier logging and access to logs
  • review records
Where this commonly fails
  • no logging obligation in supplier contracts
161R1-AU-10
Non-repudiation

Establishes that actions taken by suppliers and integrators, and the provenance claims they make, cannot later be repudiated.

Artefacts an auditor will ask for
  • signing or equivalent mechanism for supplier submissions
  • records binding an action to an external party
  • verification of supplier signatures
Where this commonly fails
  • supplier attestations accepted unsigned
  • signatures collected but never verified
161R1-AU-12
Audit Record Generation

Ensures delivered and supplier-operated components actually generate the audit records the organization needs.

Artefacts an auditor will ask for
  • acquisition requirements specifying logging capability
  • evidence delivered components log as required
  • coverage of supplier-operated components
Where this commonly fails
  • appliances delivered with logging that cannot be exported
  • supplier-operated components log to the supplier only
161R1-AU-13
Monitoring for Information Disclosure

Watches external channels for disclosure of organizational or supply chain information, including by suppliers.

Artefacts an auditor will ask for
  • defined channels monitored
  • records of disclosures found and actioned
  • notification obligations on suppliers
Where this commonly fails
  • monitoring covers own brand only, not suppliers
  • supplier breach learned from the press
161R1-AU-14
Session Audit

Captures supplier and integrator sessions where the risk warrants observing what was actually done.

Artefacts an auditor will ask for
  • criteria for when session audit applies
  • session recordings or transcripts
  • access controls on the captured sessions
Where this commonly fails
  • session capture available but never enabled for vendor access
  • captures retained without access control
161R1-AU-16
Cross-Organizational Audit Logging

Coordinates logging across organizational boundaries so that activity spanning the organization and its suppliers can be reconstructed.

Artefacts an auditor will ask for
  • agreements covering log sharing and retention with suppliers
  • evidence of correlated cross-boundary investigation
  • time synchronization agreement
Where this commonly fails
  • supplier logs unobtainable during an incident
  • retention periods incompatible across the boundary
161R1-AU-2
Event Logging

Defines the supply chain events worth logging, such as component receipt, supplier access, and changes made by integrators.

Artefacts an auditor will ask for
  • defined supply chain event types
  • logging configuration capturing them
  • review of the event list
Where this commonly fails
  • supplier activity indistinguishable from internal activity in logs
161R1-AU-3
Content of Audit Records

Requires audit records to identify which supplier, integrator or provider performed an action, not just which account.

Artefacts an auditor will ask for
  • sample records showing external party attribution
  • mapping from account to supplier organization
  • field configuration
Where this commonly fails
  • shared vendor accounts defeat attribution
  • supplier organization not recorded anywhere in the log
161R1-AU-6
Audit Review, Analysis, and Reporting

Reviews supply chain activity in the logs for signs of misuse of supplier access or unexpected change by integrators.

Artefacts an auditor will ask for
  • review procedure including supplier activity
  • dated review records
  • findings and escalation to supplier management
Where this commonly fails
  • review covers internal users only
  • findings never raised with the supplier

C-SCRM Family: Awareness and Training

161R1-AT-1
Policy and Procedures

Establishes awareness and training policy that explicitly covers cybersecurity supply chain risk and the people who make acquisition decisions.

Artefacts an auditor will ask for
  • training policy naming C-SCRM as in scope
  • identification of roles requiring C-SCRM training
  • review records
Where this commonly fails
  • training policy covers employees only, not acquisition staff or contractors
161R1-AT-2
Literacy Training and Awareness

Builds general awareness of supply chain threat, including counterfeit components, tampering and supplier compromise.

Artefacts an auditor will ask for
  • awareness content covering supply chain threat
  • completion records
  • evidence content is refreshed with current threat
Where this commonly fails
  • awareness content never mentions supply chain
  • acquisition and receiving staff outside the population
161R1-AT-3
Role-Based Training

Trains the roles that carry C-SCRM duties, including procurement, receiving, engineering and supplier management.

Artefacts an auditor will ask for
  • mapping of C-SCRM roles to required training
  • completion records per role
  • evidence training precedes the duty
Where this commonly fails
  • only the security team receives supply chain training
  • procurement staff make risk decisions untrained
161R1-AT-4
Training Records

Keeps the training record that shows who is competent to carry a C-SCRM duty, including supplier personnel where required by agreement.

Artefacts an auditor will ask for
  • training records reconciled to current role holders
  • records for supplier personnel where contractually required
  • retention period applied
Where this commonly fails
  • records held by the supplier and never obtained
  • records not reconciled after reorganization

C-SCRM Family: Configuration Management

161R1-CM-1
Policy and Procedures

Extends configuration management policy to cover components sourced externally and changes made by suppliers and integrators.

Artefacts an auditor will ask for
  • configuration management policy covering supplier change
  • contract clauses on change notification
  • review records
Where this commonly fails
  • supplier changes fall outside the policy entirely
161R1-CM-10
Software Usage Restrictions

Controls the terms and provenance under which software, including open source, may be used.

Artefacts an auditor will ask for
  • software usage policy including open source terms
  • records of licence and provenance per product
  • approval route for new software
Where this commonly fails
  • open source pulled directly into builds with no approval
  • licence terms unknown for inherited software
161R1-CM-11
User-Installed Software

Prevents users and integrators from installing software of unverified origin onto organizational systems.

Artefacts an auditor will ask for
  • installation restriction configuration
  • approved software list
  • records of exceptions and their basis
Where this commonly fails
  • integrators install tooling on production systems at will
  • restriction enforced on endpoints only
161R1-CM-12
Information Location

Identifies where organizational information sits across the supply chain, including on supplier and provider systems.

Artefacts an auditor will ask for
  • record of information locations including supplier-held copies
  • evidence covering subcontracted processing
  • update procedure on supplier change
Where this commonly fails
  • supplier subcontracting moves data with no notification
  • only primary storage identified
161R1-CM-13
Data Action Mapping

Maps the actions taken on organizational data, including by suppliers and processors, so exposure is visible.

Artefacts an auditor will ask for
  • mapping of data actions to systems and parties
  • identification of supplier processing actions
  • review on change
Where this commonly fails
  • supplier processing described only in commercial terms
  • mapping never updated after integration changes
161R1-CM-14
Signed Components

Requires and verifies cryptographic signatures on delivered software, firmware and updates before installation.

Artefacts an auditor will ask for
  • signature verification configuration or procedure
  • records of verification for sampled updates
  • handling of components that cannot be verified
Where this commonly fails
  • signatures present but never checked
  • unsigned firmware installed because verification is inconvenient
161R1-CM-2
Baseline Configuration

Establishes the baseline for delivered components so that later supplier changes can be detected against a known starting point.

Artefacts an auditor will ask for
  • baseline captured at acceptance for delivered components
  • comparison evidence against the supplier-shipped state
  • baseline update records after supplier change
Where this commonly fails
  • baseline taken after months of operation
  • no baseline for appliances and firmware
161R1-CM-3
Configuration Change Control

Brings supplier-initiated and vendor-pushed changes inside change control rather than letting them arrive unannounced.

Artefacts an auditor will ask for
  • change records for supplier-initiated changes
  • notification requirements in supplier agreements
  • evidence of review before vendor changes are applied
Where this commonly fails
  • automatic vendor updates applied with no record
  • supplier changes discovered after the fact
161R1-CM-4
Impact Analysis

Analyses the effect of supplier and component changes before they are accepted, including effects on other dependencies.

Artefacts an auditor will ask for
  • impact analyses for supplier-driven changes
  • dependency mapping used in the analysis
  • evidence the analysis influenced acceptance
Where this commonly fails
  • analysis limited to the changed component
  • dependency effects discovered in production
161R1-CM-5
Access Restrictions for Change

Restricts who, including which supplier personnel, may change components, and records when that right is exercised.

Artefacts an auditor will ask for
  • list of external personnel authorized to make changes
  • access configuration enforcing the restriction
  • records of supplier-made changes
Where this commonly fails
  • supplier holds standing change rights across environments
  • no record of which supplier engineer made a change
161R1-CM-6
Configuration Settings

Sets and verifies secure settings on delivered components rather than accepting the supplier default.

Artefacts an auditor will ask for
  • setting standards applied to delivered component types
  • compliance evidence after deployment
  • records of default credentials and services changed or disabled
Where this commonly fails
  • appliances run on shipped defaults
  • supplier forbids configuration change and the risk is unaccepted
161R1-CM-7
Least Functionality

Removes supplier-included functionality that the organization does not need and that widens the attack surface.

Artefacts an auditor will ask for
  • review of delivered functionality against need
  • records of functions and services disabled
  • acquisition requirements limiting bundled functionality
Where this commonly fails
  • vendor bundles left enabled because disabling is unsupported
  • review performed for software but not firmware
161R1-CM-8
System Component Inventory

Maintains the component inventory to the depth needed for supply chain purposes, including supplier, origin and support status.

Artefacts an auditor will ask for
  • inventory carrying supplier, origin and support status
  • reconciliation to discovery
  • procedure for updating on acquisition and disposal
Where this commonly fails
  • inventory records model but not supplier or origin
  • subcomponents and embedded software invisible
161R1-CM-9
Configuration Management Plan

Sets out how configuration will be managed across the organization and its suppliers for the life of the system.

Artefacts an auditor will ask for
  • configuration management plan naming supply chain responsibilities
  • roles split between organization and supplier
  • plan review records
Where this commonly fails
  • plan silent on who manages configuration of supplier-operated components

C-SCRM Family: Contingency Planning

161R1-CP-1
Policy and Procedures

Extends contingency policy to cover the loss of a supplier, provider or component source, not only the loss of a facility.

Artefacts an auditor will ask for
  • contingency policy addressing supplier failure
  • procedures for supplier loss scenarios
  • review records
Where this commonly fails
  • contingency policy assumes the supply chain continues
161R1-CP-11
Alternative Communications Protocols

Provides alternate communications capability where the primary protocol or its supplier becomes unavailable.

Artefacts an auditor will ask for
  • identification of alternate protocols or channels
  • test evidence of the alternate working
  • dependency analysis on the alternate
Where this commonly fails
  • alternate channel depends on the same supplier
  • alternate never tested
161R1-CP-2
Contingency Plan

Plans for continued operation when a critical supplier, integrator or component source becomes unavailable.

Artefacts an auditor will ask for
  • contingency plan with supplier failure scenarios
  • identification of critical suppliers and single points of failure
  • alternate sourcing arrangements
Where this commonly fails
  • plan lists systems but not the suppliers that keep them running
  • single-source dependencies unidentified
161R1-CP-3
Contingency Training

Trains the people who would have to act if a supplier or component source failed.

Artefacts an auditor will ask for
  • training content covering supplier failure scenarios
  • completion records for relevant roles
  • evidence of refresh after plan change
Where this commonly fails
  • training covers site recovery only
  • procurement staff untrained in emergency sourcing
161R1-CP-4
Contingency Plan Testing

Tests the supply chain elements of the contingency plan, including whether alternate sources can actually deliver.

Artefacts an auditor will ask for
  • test plan including supplier failure scenarios
  • test results and lessons
  • evidence alternate sources were contacted or validated
Where this commonly fails
  • alternate supplier named but never approached
  • supply chain scenarios never exercised
161R1-CP-6
Alternative Storage Site

Applies supply chain scrutiny to the alternate storage site and the providers that operate it.

Artefacts an auditor will ask for
  • alternate site arrangements and provider identity
  • assessment of the alternate provider
  • evidence the alternate is not subject to the same supplier dependency
Where this commonly fails
  • alternate site run by the same provider as primary
  • provider of the alternate never assessed
161R1-CP-7
Alternative Processing Site

Applies the same supply chain scrutiny to alternate processing capability and its provider.

Artefacts an auditor will ask for
  • alternate processing arrangements
  • assessment of the provider and its own dependencies
  • evidence of separation from primary dependencies
Where this commonly fails
  • alternate processing depends on the same upstream component source
  • capacity commitments unverified
161R1-CP-8
Telecommunications Services

Addresses dependence on telecommunications suppliers, including shared upstream carriers behind nominally separate services.

Artefacts an auditor will ask for
  • service arrangements with named carriers
  • analysis of shared upstream infrastructure
  • priority service arrangements where applicable
Where this commonly fails
  • two circuits from different resellers share one physical path
  • upstream carrier unknown

C-SCRM Family: Identification and Authentication

161R1-IA-1
Policy and Procedures

Extends identification and authentication policy to suppliers, integrators, provider staff and non-organizational users.

Artefacts an auditor will ask for
  • policy covering external identities
  • procedures for issuing and revoking external credentials
  • review records
Where this commonly fails
  • external identity handled informally per project
161R1-IA-2
Identification and Authentication (Organizational Users)

Ensures supplier and integrator personnel working as organizational users are individually identified and strongly authenticated.

Artefacts an auditor will ask for
  • individual accounts for external personnel
  • multi-factor configuration for external access
  • evidence of no shared vendor accounts
Where this commonly fails
  • one shared login per supplier
  • exceptions to multi-factor granted to suppliers for convenience
161R1-IA-3
Device Identification and Authentication

Authenticates devices introduced by suppliers or delivered as part of a component before they are trusted on the network.

Artefacts an auditor will ask for
  • device authentication configuration
  • enrolment records for supplier devices
  • handling of devices that cannot authenticate
Where this commonly fails
  • delivered devices auto-connect on a trusted segment
  • supplier laptops exempt from device authentication
161R1-IA-4
Identifier Management

Manages identifiers issued to external parties so they are unique, attributable and retired at engagement end.

Artefacts an auditor will ask for
  • identifier assignment records for external parties
  • uniqueness and reuse controls
  • retirement records at contract end
Where this commonly fails
  • identifiers reused across successive contractors
  • no link from identifier to supplier organization
161R1-IA-5
Authenticator Management

Manages authenticators issued to or by suppliers, including default credentials shipped with delivered components.

Artefacts an auditor will ask for
  • issuance and revocation records for external authenticators
  • evidence default credentials on delivered components are changed
  • protection of authenticators shared with suppliers
Where this commonly fails
  • shipped default credentials left in place
  • credentials emailed to supplier staff
161R1-IA-8
Identification and Authentication (Non-Organizational Users)

Handles authentication of supplier and partner users who are not organizational users but still reach organizational systems.

Artefacts an auditor will ask for
  • authentication arrangements for non-organizational users
  • federation or trust agreements and their terms
  • review of external identity providers
Where this commonly fails
  • trust extended to a supplier identity provider with no assessment
  • non-organizational users indistinguishable in logs
161R1-IA-9
Service Identification and Authentication

Authenticates the services and interfaces that supply chain parties expose or consume, not only the people.

Artefacts an auditor will ask for
  • inventory of supplier-facing services and their authentication
  • credential and certificate management for those services
  • review and rotation records
Where this commonly fails
  • service credentials embedded in supplier-supplied code
  • machine identities never rotated

C-SCRM Family: Incident Response

161R1-IR-1
Policy and Procedures

Extends incident response policy to cover incidents originating in or affecting the supply chain, and supplier reporting duties.

Artefacts an auditor will ask for
  • incident policy covering supply chain incidents
  • contractual notification obligations and timeframes
  • review records
Where this commonly fails
  • no contractual obligation on suppliers to notify
161R1-IR-2
Incident Response Training

Trains responders on supply chain incident scenarios such as compromised updates and supplier breach.

Artefacts an auditor will ask for
  • training content covering supply chain incidents
  • completion records
  • evidence of update as threat changes
Where this commonly fails
  • training scenarios cover internal compromise only
161R1-IR-3
Incident Response Testing

Exercises supply chain incident scenarios, including the parts that depend on a supplier responding.

Artefacts an auditor will ask for
  • exercise plans including supply chain scenarios
  • results and lessons
  • evidence of supplier participation where applicable
Where this commonly fails
  • exercises never involve suppliers
  • supplier contact details untested until a real incident
161R1-IR-4
Incident Handling

Handles incidents that cross the supply chain boundary, where containment depends on a party the organization does not control.

Artefacts an auditor will ask for
  • incident records involving suppliers
  • containment actions requiring supplier cooperation
  • escalation route into supplier management
Where this commonly fails
  • handling stalls waiting for supplier response with no escalation
  • supplier told nothing until the incident closes
161R1-IR-5
Incident Monitoring

Tracks supply chain incidents and their status across the organizational boundary.

Artefacts an auditor will ask for
  • tracking records for supply chain incidents
  • status updates obtained from suppliers
  • aggregate view of supplier incident history
Where this commonly fails
  • supplier incidents tracked in email only
  • no history so repeat offenders are invisible
161R1-IR-6
Incident Reporting

Reports supply chain incidents to the parties who need to know, including other users of the same supplier or component.

Artefacts an auditor will ask for
  • reporting thresholds and recipients including external bodies
  • records of reports made
  • evidence of onward notification where required
Where this commonly fails
  • reporting obligations to sector bodies unidentified
  • supplier asks for silence and gets it
161R1-IR-7
Incident Response Assistance

Secures the response assistance the organization can call on, including from suppliers and providers, before it is needed.

Artefacts an auditor will ask for
  • support arrangements with suppliers for incident response
  • contact and escalation details tested for currency
  • scope of assistance in agreements
Where this commonly fails
  • assistance assumed but not contracted
  • contact list stale
161R1-IR-8
Incident Response Plan

Includes supply chain scenarios, supplier roles and notification paths in the incident response plan.

Artefacts an auditor will ask for
  • plan sections covering supply chain incidents
  • named supplier roles and contacts
  • review and update history
Where this commonly fails
  • plan silent on what to do when the compromise arrives through an update
161R1-IR-9
Information Spillage Response

Handles spillage of organizational information into supplier environments, and of supplier information into the organization.

Artefacts an auditor will ask for
  • spillage response procedure covering supplier environments
  • records of spillage events and cleanup
  • confirmation of removal from supplier systems
Where this commonly fails
  • cleanup confirmed by supplier assertion only
  • spillage into supplier collaboration tools unrecognised

C-SCRM Family: Maintenance

161R1-MA-1
Policy and Procedures

Extends maintenance policy to cover maintenance performed by suppliers and original equipment manufacturers, on site and remotely.

Artefacts an auditor will ask for
  • maintenance policy covering supplier-performed work
  • contract terms on maintenance access and conduct
  • review records
Where this commonly fails
  • policy assumes maintenance is performed by employees
161R1-MA-2
Controlled Maintenance

Controls and records maintenance performed by suppliers, including what was replaced and where the removed part went.

Artefacts an auditor will ask for
  • maintenance records naming the supplier engineer and work performed
  • records of parts removed and their disposition
  • approval before maintenance begins
Where this commonly fails
  • parts removed by the vendor with no record
  • maintenance performed without prior approval
161R1-MA-3
Maintenance Tools

Controls the tools and diagnostic media that supplier engineers bring into the environment.

Artefacts an auditor will ask for
  • approved tool list including supplier-supplied tools
  • inspection and scanning records for incoming media
  • records of tool removal
Where this commonly fails
  • vendor laptops connected without inspection
  • tools left installed after the visit
161R1-MA-4
Nonlocal Maintenance

Governs remote maintenance performed by suppliers, which is where most supplier technical access actually occurs.

Artefacts an auditor will ask for
  • approval records per remote maintenance session
  • authentication and monitoring evidence
  • termination of access after the session
Where this commonly fails
  • permanent vendor tunnels rather than session enablement
  • sessions unmonitored
161R1-MA-5
Maintenance Personnel

Authorizes named supplier personnel rather than supplier organizations, and supervises those who are not authorized.

Artefacts an auditor will ask for
  • authorized supplier personnel list by individual
  • escort records
  • identity verification on arrival
Where this commonly fails
  • access granted on the basis of a company badge
  • list not updated when supplier staff change
161R1-MA-6
Timely Maintenance

Secures the spares and supplier support needed to restore critical components within the time the organization can tolerate.

Artefacts an auditor will ask for
  • spares holdings or supply agreements for critical components
  • support response commitments and their evidence
  • criticality analysis driving the requirement
Where this commonly fails
  • support commitments assumed rather than contracted
  • no spares for components with long lead times
161R1-MA-7
Field Maintenance

Controls maintenance performed away from the organization's facilities, where custody of the component passes to others.

Artefacts an auditor will ask for
  • field maintenance procedure and authorization
  • custody and transport records
  • inspection on return
Where this commonly fails
  • equipment returned to service without inspection
  • custody unrecorded while off site
161R1-MA-8
Maintenance Monitoring and Information Sharing

A control new in this publication: monitors maintenance activity for supply chain risk and shares what is learned with the parties who need it.

Artefacts an auditor will ask for
  • monitoring of maintenance activity for anomaly
  • records of information shared about maintenance-related risk
  • defined recipients internal and external
Where this commonly fails
  • maintenance treated as routine and never monitored
  • risk learned during maintenance never shared

C-SCRM Family: Media Protection

161R1-MP-1
Policy and Procedures

Extends media protection policy to media moving to and from suppliers and integrators.

Artefacts an auditor will ask for
  • media policy covering supplier exchange
  • procedures for media received from suppliers
  • review records
Where this commonly fails
  • policy silent on media arriving with delivered equipment
161R1-MP-4
Media Storage

Controls media held on behalf of or received from suppliers until it is sanitized or destroyed.

Artefacts an auditor will ask for
  • register of supplier-related media
  • secure storage evidence
  • access records
Where this commonly fails
  • delivered media stored in general areas
  • no register so loss is undetectable
161R1-MP-5
Media Transport

Protects media in transit between the organization and its suppliers and maintains accountability across the handover.

Artefacts an auditor will ask for
  • transport procedure including supplier handovers
  • custody and receipt records
  • protection applied in transit
Where this commonly fails
  • courier used with no manifest of contents
  • handover points with no accountability
161R1-MP-6
Media Sanitization

Sanitizes media before it leaves organizational control, including media returned to suppliers under warranty or lease.

Artefacts an auditor will ask for
  • sanitization procedure covering returns and warranty replacements
  • sanitization records with serial numbers
  • verification step
Where this commonly fails
  • failed drives returned to the vendor unsanitized
  • supplier certificate accepted without verification

C-SCRM Family: Personally Identifiable Information Processing and Transparency

161R1-PT-1
Policy and Procedures

Extends personally identifiable information processing and transparency policy to processing performed across the supply chain.

Artefacts an auditor will ask for
  • policy covering third-party processing and transparency
  • procedures for provider processing arrangements
  • review records
Where this commonly fails
  • policy assumes the organization is the only processor

C-SCRM Family: Personnel Security

161R1-PS-1
Policy and Procedures

Extends personnel security policy to the supplier, integrator and provider personnel who work on organizational systems.

Artefacts an auditor will ask for
  • personnel security policy covering external personnel
  • contract terms imposing screening and conduct requirements
  • review records
Where this commonly fails
  • policy applies to employees only
161R1-PS-3
Personnel Screening

Requires and verifies screening of supplier personnel commensurate with the access they will hold.

Artefacts an auditor will ask for
  • screening requirements by access level in contracts
  • verification evidence for supplier personnel
  • records of access granted after screening
Where this commonly fails
  • supplier asserts screening and it is never verified
  • access granted before screening completes
161R1-PS-6
Access Agreements

Puts access agreements in place with the individuals from supplier organizations who hold access, not only with their employer.

Artefacts an auditor will ask for
  • signed access agreements from external personnel
  • reconciliation to the access list
  • renewal on change
Where this commonly fails
  • agreement with the supplier company assumed to bind its staff
161R1-PS-7
External Personnel Security

Sets and enforces the personnel security requirements applying to external providers, including notification when their staff leave.

Artefacts an auditor will ask for
  • requirements imposed on providers
  • notification obligations for personnel change and their evidence
  • records of access removed on notification
Where this commonly fails
  • provider does not notify departures so access lingers
  • requirements set but compliance never checked

C-SCRM Family: Physical and Environmental Protection

161R1-PE-1
Policy and Procedures

Extends physical protection policy to supplier access, deliveries and the physical points where the supply chain meets the organization.

Artefacts an auditor will ask for
  • physical security policy covering deliveries and supplier access
  • procedures for the receiving area
  • review records
Where this commonly fails
  • policy covers staff access only
161R1-PE-16
Delivery and Removal

Controls what components enter and leave the facility and records their movement, which is the physical control point for counterfeit and tamper risk.

Artefacts an auditor will ask for
  • delivery and removal records
  • authorization for removals
  • inspection at the point of delivery
Where this commonly fails
  • deliveries accepted with no inspection or record
  • removals unauthorized and untracked
161R1-PE-17
Alternative Work Site

Applies supply chain and physical protection expectations to alternate work sites used by contractors and supplier staff.

Artefacts an auditor will ask for
  • defined requirements for alternate sites
  • assessment or attestation evidence
  • agreements with the parties working there
Where this commonly fails
  • contractor home sites outside any requirement
  • requirements defined but never assessed
161R1-PE-18
Location of System Components

Considers where components are physically placed, including whether supplier-managed equipment sits where it can be reached or observed.

Artefacts an auditor will ask for
  • placement rationale for critical components
  • assessment of physical exposure including supplier-managed equipment
  • records of relocation decisions
Where this commonly fails
  • supplier equipment placed in shared or public areas
  • placement decided by convenience only
161R1-PE-2
Physical Access Authorizations

Authorizes supplier and delivery personnel individually and keeps that authorization current.

Artefacts an auditor will ask for
  • authorized supplier personnel list
  • credential issue and return records
  • review records
Where this commonly fails
  • supplier badges issued and never returned
  • authorization by company rather than individual
161R1-PE-20
Asset Monitoring and Tracking

Tracks components physically through receipt, deployment and disposal so that substitution or diversion is detectable.

Artefacts an auditor will ask for
  • tracking method and its coverage
  • movement records from receipt to disposal
  • reconciliation between tracking and inventory
Where this commonly fails
  • tracking stops once the asset is deployed
  • reconciliation never performed
161R1-PE-23
Facility Location

Considers supply chain and threat factors in the choice of facility location, including dependence on local infrastructure and providers.

Artefacts an auditor will ask for
  • siting analysis including supply chain and infrastructure factors
  • records of the decision and its basis
  • reassessment on significant change
Where this commonly fails
  • siting decided on cost alone
  • local single-provider dependencies unexamined
161R1-PE-3
Physical Access Control

Controls physical access at the points where components and suppliers enter, including loading docks and receiving areas.

Artefacts an auditor will ask for
  • access control at delivery and receiving points
  • escort arrangements for supplier personnel
  • records of access to component storage
Where this commonly fails
  • receiving area open to anyone with a delivery
  • components staged in unsecured areas before acceptance
161R1-PE-6
Monitoring Physical Access

Monitors physical access at supply chain touch points and reviews what the monitoring shows.

Artefacts an auditor will ask for
  • monitoring coverage of receiving, storage and staging areas
  • review records
  • incident records and responses
Where this commonly fails
  • cameras present but no review
  • monitoring stops at the office and excludes the warehouse

C-SCRM Family: Planning

161R1-PL-1
Policy and Procedures

Extends planning policy so that supply chain considerations enter system planning rather than arriving at procurement.

Artefacts an auditor will ask for
  • planning policy referencing supply chain
  • procedures embedding C-SCRM in planning
  • review records
Where this commonly fails
  • supply chain first considered at purchase order stage
161R1-PL-10
Baseline Selection

Selects the control baseline with supply chain risk taken into account, so C-SCRM controls are chosen rather than assumed.

Artefacts an auditor will ask for
  • baseline selection record including C-SCRM control choices
  • rationale for inclusion or exclusion
  • approval of the selected baseline
Where this commonly fails
  • C-SCRM controls dropped in tailoring with no rationale
  • baseline selected before criticality is understood
161R1-PL-2
System Security and Privacy Plans

Records the supply chain dependencies, suppliers and C-SCRM controls of a system in its security plan.

Artefacts an auditor will ask for
  • security plan sections covering supply chain dependencies
  • identification of critical suppliers and components
  • plan review and update records
Where this commonly fails
  • plan lists controls but not the suppliers who operate them
  • dependencies unrecorded so nobody can assess concentration
161R1-PL-4
Rules of Behavior

Sets the behavioural expectations that apply to supplier, integrator and provider personnel using organizational systems.

Artefacts an auditor will ask for
  • rules applying to external personnel
  • acknowledgement records for supplier staff
  • reissue after change
Where this commonly fails
  • rules acknowledged by employees only
  • supplier staff never see the rules
161R1-PL-7
Concept of Operations

Describes how the system will actually be operated, including which parts suppliers and providers operate and the boundaries between them.

Artefacts an auditor will ask for
  • concept of operations naming operational responsibilities
  • split of duties between organization and providers
  • review on change
Where this commonly fails
  • operating model undocumented so responsibility gaps appear during incidents
161R1-PL-8
Security and Privacy Architectures

Builds supply chain considerations into architecture, including diversity, provenance and the ability to replace a supplier.

Artefacts an auditor will ask for
  • architecture artefacts addressing supplier dependency and diversity
  • analysis of substitutability for critical components
  • architecture decision records
Where this commonly fails
  • architecture locks the organization to a single supplier with no analysis
  • diversity considered for hardware but not software dependencies
161R1-PL-9
Central Management

Centrally manages the C-SCRM controls that should be consistent across the organization rather than reinvented per project.

Artefacts an auditor will ask for
  • list of centrally managed C-SCRM controls
  • evidence of consistent application
  • governance over changes to those controls
Where this commonly fails
  • each business unit runs its own supplier assessment with different standards

C-SCRM Family: Program Management

161R1-PM-10
Authorization Process

Ensures the authorization process carries supply chain risk information to the person making the decision.

Artefacts an auditor will ask for
  • authorization process description including C-SCRM inputs
  • evidence supply chain risk reached the decision maker
  • conditions imposed relating to suppliers
Where this commonly fails
  • authorization packages omit supplier risk entirely
161R1-PM-11
Mission and Business Process Definition

Defines mission and business processes in a way that exposes which supply chain elements they actually depend on.

Artefacts an auditor will ask for
  • process definitions with their supply chain dependencies
  • criticality attached to those dependencies
  • review on process change
Where this commonly fails
  • processes documented without naming the suppliers that enable them
161R1-PM-12
Insider Threat Program

Extends the insider threat programme to insiders introduced through the supply chain, including contractor and integrator personnel.

Artefacts an auditor will ask for
  • programme scope covering supplier personnel
  • legal and privacy basis for that scope
  • referral and case records
Where this commonly fails
  • programme covers employees only while integrators hold deeper access
161R1-PM-13
Security and Privacy Workforce

Builds the workforce capability needed to do C-SCRM work, including acquisition and supplier management skills.

Artefacts an auditor will ask for
  • capability requirements for C-SCRM roles
  • development and recruitment plans
  • competence records
Where this commonly fails
  • supplier risk assessed by staff with no training in it
161R1-PM-14
Testing, Training, and Monitoring

Plans and coordinates testing, training and monitoring so that C-SCRM activities are scheduled rather than incidental.

Artefacts an auditor will ask for
  • integrated schedule of C-SCRM testing, training and monitoring
  • evidence activities occurred as scheduled
  • adjustment records
Where this commonly fails
  • activities happen only in response to an incident
161R1-PM-15
Security and Privacy Groups and Associations

Maintains contact with external groups that share supply chain threat and vulnerability information.

Artefacts an auditor will ask for
  • memberships and participation records
  • information received and how it was used
  • internal distribution of what is learned
Where this commonly fails
  • membership held but never used
  • information received and never distributed
161R1-PM-16
Threat Awareness Program

Maintains awareness of threat actors targeting the supply chain and feeds that awareness into decisions.

Artefacts an auditor will ask for
  • threat awareness sources and products
  • evidence supply chain threat informs supplier decisions
  • distribution to acquisition and engineering
Where this commonly fails
  • threat awareness stops at the security team
161R1-PM-17
Protecting Controlled Unclassified Information on External Systems

Sets and enforces the terms under which external parties may hold controlled unclassified information.

Artefacts an auditor will ask for
  • identification of external systems holding such information
  • contract terms imposing protection requirements
  • verification of compliance
Where this commonly fails
  • requirements flowed down but never verified
  • holdings unidentified so terms are unenforceable
161R1-PM-18
Privacy Program Plan

Includes supply chain processing in the privacy programme plan, since much personal data is handled by providers.

Artefacts an auditor will ask for
  • privacy programme plan covering supplier processing
  • inventory of processors
  • oversight arrangements
Where this commonly fails
  • privacy plan assumes processing is internal
161R1-PM-19
Privacy Program Leadership Role

Names the leader accountable for privacy including the privacy risk carried by the supply chain.

Artefacts an auditor will ask for
  • appointment and authority record
  • reporting line
  • evidence of involvement in supplier decisions
Where this commonly fails
  • privacy leader unaware of processors engaged by business units
161R1-PM-2
Information Security Program Leadership Role

Places accountability for the cybersecurity supply chain programme with a named leader who has the authority to act on it.

Artefacts an auditor will ask for
  • appointment record naming the accountable leader
  • statement of authority and budget
  • reporting line to executive level
Where this commonly fails
  • accountability spread across procurement and security with no single owner
161R1-PM-20
Dissemination of Privacy Program Information

Makes clear to individuals how their information is handled, including by suppliers and providers acting for the organization.

Artefacts an auditor will ask for
  • published privacy information covering third-party processing
  • review of accuracy against actual processors
  • update process
Where this commonly fails
  • notice silent on providers that hold the data
161R1-PM-21
Accounting of Disclosures

Accounts for disclosures made to and through supply chain parties.

Artefacts an auditor will ask for
  • disclosure records including transfers to providers
  • retention of the accounting
  • process for responding to requests
Where this commonly fails
  • transfers to processors not treated as disclosures
161R1-PM-22
Personally Identifiable Information Quality Management

Maintains data quality across the supply chain, where data passes through providers who may alter or degrade it.

Artefacts an auditor will ask for
  • quality requirements imposed on processors
  • quality checks on data returned from providers
  • correction process spanning the chain
Where this commonly fails
  • quality assumed for data processed externally
  • corrections not propagated to providers
161R1-PM-23
Data Governance Body

Gives the data governance body oversight of data that moves into and through the supply chain.

Artefacts an auditor will ask for
  • governance body terms of reference covering third-party data
  • decision records on supplier data arrangements
  • membership including procurement and privacy
Where this commonly fails
  • governance body never sees supplier data arrangements
161R1-PM-25
Minimization of Personally Identifiable Information Used in Testing, Training, and Research

Prevents real personal data being handed to suppliers and developers for testing, training or research.

Artefacts an auditor will ask for
  • policy prohibiting production data in test environments
  • technical controls or masking evidence
  • records of approved exceptions
Where this commonly fails
  • production data copied to supplier test environments as routine
  • masking applied inconsistently
161R1-PM-26
Complaint Management

Handles complaints that arise from supply chain handling of information and routes them to the responsible party.

Artefacts an auditor will ask for
  • complaint process covering third-party handling
  • records of complaints and outcomes
  • escalation route to suppliers
Where this commonly fails
  • complaints about a provider have nowhere to go
161R1-PM-27
Privacy Reporting

Reports on privacy including the risk and incidents arising from the supply chain.

Artefacts an auditor will ask for
  • privacy reports covering third-party processing
  • recipients and frequency
  • evidence reports drive action
Where this commonly fails
  • reporting covers internal processing only
161R1-PM-28
Risk Framing

Frames supply chain risk explicitly: the assumptions, constraints, tolerances and priorities that govern how it is judged.

Artefacts an auditor will ask for
  • risk framing statement covering supply chain
  • recorded assumptions and constraints
  • review of the framing
Where this commonly fails
  • framing implicit so different teams judge supplier risk differently
161R1-PM-29
Risk Management Program Leadership Roles

Names the leadership roles that own supply chain risk and distinguishes them from those who own the systems.

Artefacts an auditor will ask for
  • defined risk leadership roles including C-SCRM
  • appointment records
  • authority and escalation paths
Where this commonly fails
  • roles named in policy but unfilled
161R1-PM-3
Information Security and Privacy Resources

Funds C-SCRM as a line of work rather than expecting it from existing capacity.

Artefacts an auditor will ask for
  • budget lines covering C-SCRM activity
  • staffing allocated to supplier assessment and monitoring
  • evidence resource requests are considered in planning
Where this commonly fails
  • C-SCRM assigned with no resource so it happens only after an incident
161R1-PM-30
Supply Chain Risk Management Strategy

Sets the organizational C-SCRM strategy and implementation plan that everything else in the programme derives from.

Artefacts an auditor will ask for
  • C-SCRM strategy with objectives and scope
  • implementation plan with owners and milestones
  • review and update records
  • approval at executive level
Where this commonly fails
  • strategy written once and never operationalized
  • no implementation plan behind the strategy
161R1-PM-31
Continuous Monitoring Strategy

Defines what supply chain risk is monitored continuously, how often, and what triggers action.

Artefacts an auditor will ask for
  • monitoring strategy naming supply chain metrics and frequencies
  • defined thresholds and triggers
  • evidence of monitoring output and response
Where this commonly fails
  • monitoring strategy lists tools rather than what is being watched
161R1-PM-32
Purposing

Ensures systems and components are used only for the purpose they were acquired and assessed for, since repurposing invalidates the supply chain assessment.

Artefacts an auditor will ask for
  • records of intended purpose per system or component
  • approval process for repurposing
  • reassessment evidence when purpose changes
Where this commonly fails
  • components repurposed into higher-criticality use with no reassessment
161R1-PM-4
Plan of Action and Milestones Process

Runs a process that carries supply chain weaknesses through to closure at organizational level, not only per system.

Artefacts an auditor will ask for
  • organization-level plan of action including supply chain items
  • process for escalation and closure
  • aggregate reporting on open items
Where this commonly fails
  • supply chain findings tracked per project and never aggregated
161R1-PM-5
System Inventory

Maintains the organizational system inventory in a form that supports supply chain questions such as which systems depend on a given supplier.

Artefacts an auditor will ask for
  • system inventory linked to suppliers and critical components
  • query evidence answering supplier exposure questions
  • update procedure
Where this commonly fails
  • inventory cannot answer which systems a compromised supplier touches
161R1-PM-6
Measures of Performance

Measures whether the C-SCRM programme is actually reducing risk rather than producing activity.

Artefacts an auditor will ask for
  • defined C-SCRM measures and their definitions
  • reported values over time
  • evidence measures inform decisions
Where this commonly fails
  • measures count assessments completed rather than risk reduced
161R1-PM-7
Enterprise Architecture

Reflects supply chain dependency and concentration in the enterprise architecture so that structural risk is visible.

Artefacts an auditor will ask for
  • architecture views showing supplier and component dependency
  • concentration analysis
  • use of the architecture in investment decisions
Where this commonly fails
  • architecture models technology but not who supplies it
161R1-PM-8
Critical Infrastructure Plan

Addresses supply chain dependency in the critical infrastructure plan, including upstream providers the organization does not contract with directly.

Artefacts an auditor will ask for
  • critical infrastructure plan naming supply chain dependencies
  • analysis of upstream and sub-tier dependency
  • coordination arrangements
Where this commonly fails
  • plan covers own assets only
  • sub-tier dependencies unmapped
161R1-PM-9
Risk Management Strategy

Sets how supply chain risk is framed, assessed, responded to and monitored as part of the organizational risk strategy.

Artefacts an auditor will ask for
  • risk management strategy including supply chain
  • risk appetite or tolerance statements covering supplier risk
  • evidence of integration with enterprise risk
Where this commonly fails
  • supply chain risk run separately from enterprise risk with no aggregation

C-SCRM Family: Risk Assessment

161R1-RA-1
Policy and Procedures

Extends risk assessment policy so that supply chain risk is assessed as a class of risk in its own right.

Artefacts an auditor will ask for
  • risk assessment policy naming supply chain risk
  • assessment procedures for suppliers and components
  • review records
Where this commonly fails
  • supply chain risk folded into vendor management with no security assessment
161R1-RA-10
Threat Hunting

Hunts for adversary activity introduced through the supply chain rather than waiting for an alert.

Artefacts an auditor will ask for
  • hunt plans including supply chain hypotheses
  • hunt records and findings
  • use of supplier and component intelligence in hunts
Where this commonly fails
  • hunting focuses on perimeter intrusion only
  • supplier compromise indicators never hunted for
161R1-RA-2
Security Categorization

Categorizes systems in a way that carries through to the criticality of the components and suppliers they depend on.

Artefacts an auditor will ask for
  • categorization records
  • linkage from system category to component and supplier criticality
  • review on change
Where this commonly fails
  • categorization stops at the system and never reaches its dependencies
161R1-RA-3
Risk Assessment

Assesses supply chain risk across the enterprise, mission and system levels, and keeps it current.

Artefacts an auditor will ask for
  • supply chain risk assessments at each level
  • methodology covering supplier, component and process risk
  • update evidence on change
  • risk register entries with owners
Where this commonly fails
  • one assessment covering all suppliers equally
  • assessment never repeated after supplier change
161R1-RA-5
Vulnerability Monitoring and Scanning

Monitors vulnerabilities in acquired and third-party components, including dependencies the organization did not choose directly.

Artefacts an auditor will ask for
  • coverage of acquired and open source components
  • dependency or bill of materials data driving the monitoring
  • remediation records including supplier-dependent fixes
Where this commonly fails
  • scanning covers deployed systems but not embedded dependencies
  • fixes blocked on the supplier with no tracking
161R1-RA-7
Risk Response

Responds to supply chain risk with decisions that are recorded, owned and revisited, including decisions to accept.

Artefacts an auditor will ask for
  • response decisions per supply chain risk
  • approver at the appropriate level
  • tracking of mitigations to closure
Where this commonly fails
  • acceptance by default because no alternative supplier was sought
161R1-RA-9
Criticality Analysis

Identifies which components and suppliers actually matter, so that C-SCRM effort concentrates where failure would hurt.

Artefacts an auditor will ask for
  • criticality analysis method and results
  • identification of critical components and single points of failure
  • use of the results to prioritize controls
  • review on change
Where this commonly fails
  • every supplier treated as equally critical so nothing is prioritized
  • analysis performed once and never revisited

C-SCRM Family: Supply Chain Risk Management

161R1-SR-1
Policy and Procedures

Establishes the supply chain risk management policy and procedures that the rest of the SR family operates under.

Artefacts an auditor will ask for
  • C-SCRM policy with approval and scope
  • procedures implementing it
  • named roles and responsibilities
  • review and update records
Where this commonly fails
  • policy exists with no procedures behind it
  • policy owner unnamed
161R1-SR-10
Inspection of Systems or Components

Inspects systems and components at defined points to detect tampering, substitution or counterfeit.

Artefacts an auditor will ask for
  • inspection procedure and the points at which it applies
  • inspection records with results
  • criteria for what constitutes a failed inspection
  • escalation for failed inspections
Where this commonly fails
  • inspection performed only when something looks wrong
  • inspection criteria undefined so results are subjective
161R1-SR-11
Component Authenticity

Establishes an anti-counterfeit policy and the means to detect and report counterfeit components.

Artefacts an auditor will ask for
  • anti-counterfeit policy and procedures
  • authenticity verification methods used
  • records of suspected counterfeits and their reporting
  • training for staff who receive components
Where this commonly fails
  • authenticity assumed because the reseller is authorized
  • suspected counterfeits discarded rather than reported
161R1-SR-12
Component Disposal

Disposes of components so that organizational information and the components themselves cannot re-enter the supply chain uncontrolled.

Artefacts an auditor will ask for
  • disposal procedure covering data and physical component
  • disposal records with serial numbers
  • controls preventing resale of components carrying organizational identity
  • third-party disposal supplier assessment
Where this commonly fails
  • components sold on with organizational markings intact
  • disposal supplier unassessed
161R1-SR-13
Supplier Inventory

A control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.

Artefacts an auditor will ask for
  • supplier inventory with the systems and components each supports
  • criticality attached to each supplier
  • update procedure on supplier change
  • sub-tier supplier information where obtainable
Where this commonly fails
  • supplier list held by procurement with no link to systems
  • sub-tier suppliers entirely unknown
  • inventory cannot answer which systems a given supplier touches
161R1-SR-2
Supply Chain Risk Management Plan

Requires a plan for managing supply chain risk for the system, reviewed and updated and protected from disclosure.

Artefacts an auditor will ask for
  • system-level C-SCRM plan
  • review and update records
  • protection and access control on the plan
  • linkage to the risk register
Where this commonly fails
  • one generic plan reused for every system
  • plan never updated after supplier change
161R1-SR-3
Supply Chain Controls and Processes

Establishes the processes that identify and address supply chain risk for the system, in coordination with its suppliers.

Artefacts an auditor will ask for
  • defined supply chain processes for the system
  • evidence of coordination with suppliers
  • records of risks identified and addressed
  • flow down to sub-tier where required
Where this commonly fails
  • processes defined centrally and unused by the projects
  • sub-tier suppliers outside every process
161R1-SR-4
Provenance

Establishes and maintains provenance for systems, components and associated data so origin and change history are known.

Artefacts an auditor will ask for
  • provenance records for critical components
  • evidence of origin and chain of custody
  • update of provenance as components change
  • bill of materials where available
Where this commonly fails
  • provenance known only as far as the reseller
  • provenance captured at purchase and never maintained
161R1-SR-5
Acquisition Strategies, Tools, and Methods

Uses acquisition strategy, contract tools and purchasing methods to reduce supply chain risk before it enters the organization.

Artefacts an auditor will ask for
  • acquisition strategies differentiated by criticality
  • contract tools and clauses in use
  • evidence of application in real purchases
  • supplier selection criteria including security
Where this commonly fails
  • one purchasing approach for critical and trivial alike
  • clauses available but rarely used
161R1-SR-6
Supplier Assessments and Reviews

Assesses and reviews suppliers, at a depth matched to what they supply and the access they hold.

Artefacts an auditor will ask for
  • assessment methodology and tiering by criticality
  • assessment records per supplier
  • review cycle evidence
  • findings and their treatment
Where this commonly fails
  • all suppliers assessed with the same questionnaire
  • assessment at onboarding only
161R1-SR-7
Supply Chain Operations Security

Applies operations security to acquisition so that adversaries cannot learn what is being bought, from whom and when.

Artefacts an auditor will ask for
  • operations security measures applied to acquisition
  • controls on disclosure of supplier and delivery detail
  • awareness for procurement staff
Where this commonly fails
  • delivery schedules and destinations broadly visible
  • supplier relationships publicised in detail
161R1-SR-8
Notification Agreements

Establishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.

Artefacts an auditor will ask for
  • notification clauses with defined triggers and timeframes
  • evidence of notifications received
  • escalation route when notification fails
  • coverage of sub-tier events
Where this commonly fails
  • notification obligation absent or without a timeframe
  • notifications received and not routed anywhere
161R1-SR-9
Tamper Resistance and Detection

Applies tamper resistance and detection to components across development, transport and operation.

Artefacts an auditor will ask for
  • tamper resistance and detection measures in use
  • inspection procedures and records
  • handling of components found tampered with
Where this commonly fails
  • tamper evidence applied but never inspected on receipt
  • no procedure for a component that fails inspection

C-SCRM Family: System and Communications Protection

161R1-SC-1
Policy and Procedures

Extends system and communications protection policy to the connections and components that the supply chain introduces.

Artefacts an auditor will ask for
  • policy covering supplier connections and delivered components
  • procedures for protecting those connections
  • review records
Where this commonly fails
  • policy silent on supplier connectivity
161R1-SC-18
Mobile Code

Controls mobile code that arrives with delivered components or from supplier-hosted content.

Artefacts an auditor will ask for
  • permitted mobile code definition
  • controls on supplier-hosted content and embedded code
  • monitoring or blocking evidence
Where this commonly fails
  • supplier portals require permissive browser settings
  • embedded code in delivered products unexamined
161R1-SC-27
Platform-Independent Applications

Favours platform independence so that dependency on a single supplier's platform does not become structural.

Artefacts an auditor will ask for
  • portability requirements in acquisition
  • analysis of platform dependency for critical applications
  • migration feasibility assessments
Where this commonly fails
  • applications bound to one supplier platform with no exit analysis
161R1-SC-28
Protection of Information at Rest

Protects organizational information at rest wherever it sits, including on supplier and provider systems.

Artefacts an auditor will ask for
  • identification of at-rest locations including provider systems
  • protection applied and evidence of it
  • key management arrangements where the provider holds keys
Where this commonly fails
  • provider holds both data and keys with no analysis of that concentration
  • backups at providers unprotected
161R1-SC-29
Heterogeneity

Uses diversity of components and suppliers so a single compromised source cannot affect everything at once.

Artefacts an auditor will ask for
  • analysis of component and supplier concentration
  • diversity decisions and their rationale
  • identification of common-mode dependencies
Where this commonly fails
  • standardization pursued to the point of a single point of failure
  • diversity claimed while all products share one upstream component
161R1-SC-30
Concealment and Misdirection

Uses concealment and misdirection so that supply chain and system detail useful to an adversary is not freely observable.

Artefacts an auditor will ask for
  • assessment of what supply chain detail is externally observable
  • concealment measures applied
  • review of public and partner-facing disclosure
Where this commonly fails
  • detailed technology and supplier stack published in marketing material
161R1-SC-36
Distributed Processing and Storage

Distributes processing and storage so that the failure or compromise of one supplier or site does not take everything with it.

Artefacts an auditor will ask for
  • distribution design and rationale
  • analysis of shared dependencies across the distributed set
  • test evidence of operation with one part unavailable
Where this commonly fails
  • distributed sites all served by the same provider
  • distribution designed for capacity rather than resilience
161R1-SC-37
Out-of-Band Channels

Maintains out-of-band channels for the information and credentials that must not travel the same path as the thing they protect.

Artefacts an auditor will ask for
  • identification of information requiring out-of-band handling
  • channel arrangements including with suppliers
  • evidence of use
Where this commonly fails
  • verification data sent by the same channel as the delivery it verifies
  • out-of-band channel provided by the same supplier
161R1-SC-38
Operations Security

Applies operations security so that supply chain activity does not reveal capability, dependency or timing to an adversary.

Artefacts an auditor will ask for
  • operations security assessment covering acquisition activity
  • controls on disclosure in tenders and procurement
  • training for staff involved
Where this commonly fails
  • tender documents reveal architecture and dependencies publicly
161R1-SC-4
Information in Shared Resources

Prevents information leaking through resources shared with suppliers, providers or other tenants.

Artefacts an auditor will ask for
  • identification of resources shared with external parties
  • controls preventing residual data exposure
  • evidence for multi-tenant provider platforms
Where this commonly fails
  • multi-tenant provider assumed safe with no evidence
  • shared development environments hold production data
161R1-SC-47
Alternative Communications Paths

Provides alternative communications paths that do not share the same supplier or physical route as the primary.

Artefacts an auditor will ask for
  • identification of primary and alternate paths and their suppliers
  • analysis of shared physical route or upstream carrier
  • test evidence
Where this commonly fails
  • alternate path shares the same duct or upstream carrier
  • alternate never exercised
161R1-SC-5
Denial-of-Service Protection

Addresses denial of service risk that arrives through or depends on supply chain parties.

Artefacts an auditor will ask for
  • protection arrangements and where they are provided from
  • dependency analysis on the protecting provider
  • test or exercise evidence
Where this commonly fails
  • protection provided by the same party whose failure is the risk
  • no arrangement for provider-side outage
161R1-SC-7
Boundary Protection

Controls and monitors the boundaries where supplier, integrator and provider connections meet the organization.

Artefacts an auditor will ask for
  • identification of supply chain boundaries and connections
  • boundary device rule sets for those connections
  • monitoring evidence
  • review of the connection inventory
Where this commonly fails
  • supplier connections terminate inside the trusted network
  • connections accumulate with no review
161R1-SC-8
Transmission Confidentiality and Integrity

Protects information in transit between the organization and its suppliers, providers and integrators.

Artefacts an auditor will ask for
  • inventory of supply chain transmission paths and their protection
  • cipher and protocol configuration
  • evidence weak protocols are disabled on those paths
Where this commonly fails
  • supplier file transfer over unprotected channels
  • protection assumed because the link is private

C-SCRM Family: System and Information Integrity

161R1-SI-1
Policy and Procedures

Extends system and information integrity policy to cover integrity of components and updates arriving from the supply chain.

Artefacts an auditor will ask for
  • integrity policy covering delivered components and updates
  • procedures for verifying what arrives
  • review records
Where this commonly fails
  • policy addresses running systems but not what is installed onto them
161R1-SI-12
Information Management and Retention

Manages retention and disposal of information across the supply chain, including information held by providers after the engagement.

Artefacts an auditor will ask for
  • retention requirements imposed on providers
  • evidence of disposal at engagement end
  • identification of provider-held information
Where this commonly fails
  • provider retains data indefinitely after contract end
  • disposal asserted with no confirmation
161R1-SI-2
Flaw Remediation

Remediates flaws in acquired components, where the fix depends on a supplier the organization does not control.

Artefacts an auditor will ask for
  • patch process covering acquired and embedded components
  • tracking of fixes pending with suppliers
  • compensating controls where no fix is available
  • escalation route to suppliers
Where this commonly fails
  • flaws in supplier products tracked nowhere because the fix is not ours
  • no compensating control while waiting for a supplier fix
161R1-SI-20
Tainting

Uses tainting techniques so that unauthorized exfiltration of organizational information through the supply chain can be detected.

Artefacts an auditor will ask for
  • tainting approach and where it is applied
  • detection arrangements
  • records of any detections and response
Where this commonly fails
  • technique described but never deployed
  • no detection route for tainted data if it surfaces
161R1-SI-3
Malicious Code Protection

Protects against malicious code introduced through delivered components, updates and supplier channels.

Artefacts an auditor will ask for
  • scanning of incoming components, media and updates
  • protection coverage on supplier-connected systems
  • records of detections in the delivery path
Where this commonly fails
  • updates trusted because they came from the vendor
  • incoming media scanned only when convenient
161R1-SI-4
System Monitoring

Monitors for behaviour indicating compromise arriving through the supply chain, such as unexpected outbound activity from delivered components.

Artefacts an auditor will ask for
  • monitoring coverage of delivered and supplier-operated components
  • detection use cases for supply chain compromise
  • alert records and triage
Where this commonly fails
  • delivered appliances excluded from monitoring
  • outbound connections from vendor equipment unexamined
161R1-SI-5
Security Alerts, Advisories, and Directives

Receives and acts on advisories concerning acquired components and the suppliers behind them.

Artefacts an auditor will ask for
  • named sources covering acquired components
  • records of advisories received and actioned
  • supplier notification obligations
Where this commonly fails
  • advisory sources cover the operating system but not the appliances and libraries in use
161R1-SI-7
Software, Firmware, and Information Integrity

Verifies the integrity of software and firmware received from suppliers, before and after installation.

Artefacts an auditor will ask for
  • integrity verification method and evidence for received software and firmware
  • baseline hashes or signatures retained
  • periodic re-verification records
Where this commonly fails
  • integrity checked at install and never again
  • firmware integrity unverifiable and the risk unaccepted

C-SCRM Family: System and Services Acquisition

161R1-SA-1
Policy and Procedures

Extends system and services acquisition policy so that security and supply chain requirements enter acquisition from the start.

Artefacts an auditor will ask for
  • acquisition policy including security and C-SCRM requirements
  • procedures for supplier selection and contracting
  • review records
Where this commonly fails
  • security requirements added after supplier selection
161R1-SA-10
Developer Configuration Management

Requires the developer or supplier to manage configuration of what they deliver, and to prove it.

Artefacts an auditor will ask for
  • developer configuration management requirements in contract
  • evidence of the developer's configuration management such as version and change records
  • integrity verification of delivered items
Where this commonly fails
  • delivered builds not reproducible
  • developer change records unavailable to the organization
161R1-SA-11
Developer Testing and Evaluation

Requires developers and suppliers to test what they deliver and to make the results available.

Artefacts an auditor will ask for
  • testing requirements in contract
  • developer test plans and results received
  • evidence of flaw remediation by the developer
  • independent verification where warranted
Where this commonly fails
  • test results asserted in a summary letter with no detail
  • flaws found by the developer never disclosed
161R1-SA-15
Development Process, Standards, and Tools

Sets expectations on the developer's own process, standards and tooling, since delivered security depends on them.

Artefacts an auditor will ask for
  • required development standards in contract
  • evidence of the developer's process and tool use
  • review of the developer's own supply chain for tooling
Where this commonly fails
  • process requirements unverified
  • developer tool chain never considered as a risk
161R1-SA-16
Developer-Provided Training

Obtains the training needed to operate and secure delivered components correctly.

Artefacts an auditor will ask for
  • training requirements in contract
  • delivery records
  • evidence knowledge transferred to the operating team
Where this commonly fails
  • training delivered to a project team that then disbands
  • no training obtained for security-relevant features
161R1-SA-17
Developer Security and Privacy Architecture and Design

Requires the developer to produce architecture and design evidence sufficient for the organization to judge the security of what it is buying.

Artefacts an auditor will ask for
  • architecture and design deliverables required and received
  • review records of those deliverables
  • traceability from requirement to design
Where this commonly fails
  • design evidence withheld as proprietary and the risk unaccepted
  • deliverables received but never reviewed
161R1-SA-2
Allocation of Resources

Allocates the resources needed to meet supply chain security requirements as part of the acquisition, not as an afterthought.

Artefacts an auditor will ask for
  • resource allocation records within acquisitions
  • evidence C-SCRM cost is included in business cases
  • approval records
Where this commonly fails
  • supply chain assurance unfunded so it does not happen
161R1-SA-20
Customized Development of Critical Components

Considers building or customizing critical components where the market cannot supply them at the assurance level required.

Artefacts an auditor will ask for
  • identification of components where market supply is inadequate
  • decision records on custom development
  • assurance arrangements for custom components
Where this commonly fails
  • critical dependency on a component nobody has assessed and no alternative considered
161R1-SA-21
Developer Screening

Requires screening of the developer personnel who will have access to what matters, and verifies it.

Artefacts an auditor will ask for
  • screening requirements in contract by access level
  • verification evidence
  • records of personnel covered
Where this commonly fails
  • screening asserted by the developer and never verified
  • subcontracted developers outside the requirement
161R1-SA-22
Unsupported System Components

Manages components the supplier no longer supports, which is where supply chain risk quietly accumulates.

Artefacts an auditor will ask for
  • inventory with support status and end-of-support dates
  • replacement plans and funding
  • approvals and mitigations for continued use
  • alternative support arrangements where used
Where this commonly fails
  • support status untracked until a vulnerability is published
  • continued use with no approval or compensating control
161R1-SA-3
System Development Life Cycle

Runs C-SCRM activities at defined points across the development life cycle, including for acquired components.

Artefacts an auditor will ask for
  • life cycle definition with C-SCRM activities and gates
  • evidence activities occurred at those points
  • roles assigned across the life cycle
Where this commonly fails
  • C-SCRM activity concentrated at purchase with nothing during development or disposal
161R1-SA-4
Acquisition Process

Puts security and supply chain requirements into the contract, including the evidence the supplier must provide.

Artefacts an auditor will ask for
  • contract templates carrying security and C-SCRM requirements
  • evidence of requirements in executed contracts
  • acceptance criteria tied to those requirements
  • supplier deliverables such as documentation and bills of materials
Where this commonly fails
  • requirements in the template but absent from signed contracts
  • no acceptance criteria so requirements are unenforceable
161R1-SA-5
System Documentation

Obtains and retains the documentation needed to operate, secure and assess acquired components over their life.

Artefacts an auditor will ask for
  • documentation received per acquisition
  • retention and access arrangements
  • records where documentation was refused and what was done
Where this commonly fails
  • documentation promised but never delivered
  • documentation held by a departed integrator
161R1-SA-8
Security and Privacy Engineering Principles

Applies engineering principles to acquired and integrated components, not only to what is built in house.

Artefacts an auditor will ask for
  • engineering principles adopted
  • evidence of application in integration design
  • review records for acquired component integration
Where this commonly fails
  • principles applied to in-house build while integrations bypass them
161R1-SA-9
External System Services

Governs external service providers across their life cycle, including the security roles each party holds.

Artefacts an auditor will ask for
  • inventory of external services
  • agreements defining security roles and responsibilities
  • monitoring and assessment evidence
  • exit and transition arrangements
Where this commonly fails
  • responsibilities assumed rather than defined
  • no exit plan so provider change is impossible
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-161 Rev 1 framework page.