NIST 800-53 Rev 5

424 controls available

IR-6(3)moderatehigh

Supply Chain Coordination

Incident Response

Control Statement

Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.

Discussion

Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Entities that provide supply chain governance include the Federal Acquisition Security Council (FASC). Supply chain incidents include compromises or breaches that involve information technology products, system components, development processes or personnel, distribution processes, or warehousing facilities. Organizations determine the appropriate information to share and consider the value gained from informing external organizations about supply chain incidents, including the ability to improve processes or to identify the root cause of an incident.

Framework
NIST SP 800-53 Rev 5
Family
Incident Response
Baselines
moderate, high

Related Frameworks

4 paths across 2 frameworks
SCF1 mapping
IRO-10.4Supply Chain Coordination
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI3 mappings
CCI-002793
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004156
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002790
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

No STIGs in the current catalog reference any CCI mapped to this control.