NIST 800-53 Rev 5

424 controls available

SR-2(1)lowmoderatehigh

Establish SCRM Team

Supply Chain Risk Management

Control Statement

Establish a supply chain risk management team consisting of {{ insert: param, sr-02.01_odp.01 }} to lead and support the following SCRM activities: {{ insert: param, sr-02.01_odp.02 }}.

Discussion

To implement supply chain risk management plans, organizations establish a coordinated, team-based approach to identify and assess supply chain risks and manage these risks by using programmatic and technical mitigation techniques. The team approach enables organizations to conduct an analysis of their supply chain, communicate with internal and external partners or stakeholders, and gain broad consensus regarding the appropriate resources for SCRM. The SCRM team consists of organizational personnel with diverse roles and responsibilities for leading and supporting SCRM activities, including risk executive, information technology, contracting, information security, privacy, mission or business, legal, supply chain and logistics, acquisition, business continuity, and other relevant functions. Members of the SCRM team are involved in various aspects of the SDLC and, collectively, have an awareness of and provide expertise in acquisition processes, legal practices, vulnerabilities, threats, and attack vectors, as well as an understanding of the technical aspects and dependencies of systems. The SCRM team can be an extension of the security and privacy risk management processes or be included as part of an organizational risk management team.

Framework
NIST SP 800-53 Rev 5
Family
Supply Chain Risk Management
Baselines
low, moderate, high

Related Frameworks

17 paths across 2 frameworks
SCF1 mapping
TPM-03Supply Chain Risk Management (SCRM)
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI16 mappings
CCI-005077
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-005078
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-005079
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003145
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003146
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003147
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003148
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004787
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004788
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004789
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

+6 more (top 10 by confidence shown)

Related STIGs

No STIGs in the current catalog reference any CCI mapped to this control.