NIST SP 800-53 Rev 5
SR - Supply Chain Risk Management

NIST SP 800-53 Rev 5 NIST800-SR-11: SR-11 Component Authenticity

a. Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and b. Report counterfeit system components to [Selection (one or more): source of counterfeit component; [Assignment: organization-defined external reporting organizations]; [Assignment: organization-defined personnel or roles]].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 236 controls across 103 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

SASB Standards · 6 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-3 Leadership and Governance (LG)
  • SASB-BMI-3 Supply Chain Management
  • SASB-LG-2 Systemic Risk Management
  • SASB-LG-3 Critical Incident Risk Management
  • SASB-LG-5 Systemic Risk Management
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P1-S2 Risk-Management Systems
  • P2-S1 Partnership
  • ISO-20400-4.5 Key considerations for sustainable procurement
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 23894:2023 · 4 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • ISO23894-A.6 AI System Security

ISO/IEC 27003:2017 · 4 controls

  • ISO27003-4.2 Understanding the needs and expectations of interested parties
  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.1 Operational planning and control
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-21 Supply chain risk management for critical components
  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • SOCI-S30AC Obligation to adopt a CIRMP
  • SOCI-S30AD Compliance with CIRMP
  • SOCI-S30AE Annual review of CIRMP

Solvency II · 4 controls

  • SII-P2-09 Outsourcing Requirements
  • SII-P2-11 Remuneration Policy
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

FedRAMP High · 3 controls

  • SR-11 Component Authenticity (SR-11)
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))

FedRAMP Moderate · 3 controls

  • SR-11 Component Authenticity (SR-11)
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-5.6 Risk management
  • ISO-15189-6.8 Externally provided products and services
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-SA-04 Security Risk Treatment Planning

NIST SP 1800-32 · 3 controls

PCI P2PE · 3 controls

  • PCI-P2PE-16 Due diligence and onboarding
  • PCI-P2PE-18 Ongoing monitoring and assessment
  • PCI-P2PE-19 Concentration risk management

PCI PIN Security · 3 controls

  • PCI-PIN-16 Due diligence and onboarding
  • PCI-PIN-18 Ongoing monitoring and assessment
  • PCI-PIN-19 Concentration risk management

PCI SSF · 3 controls

  • PCI-SSF-03 Risk appetite and tolerance for IT risk
  • PCI-SSF-16 Due diligence and onboarding
  • PCI-SSF-17 Contractual security requirements
  • RMI-DD-3 Red Flag Review
  • RMI-MS-2 Cobalt Standard
  • RMI-RMAP-2 Risk-Based Audit Approach

SOC 2 · 3 controls

  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC-CY-DC1 Nature of Business and Operations
  • SOC-CY-DC3 Cybersecurity Risk Management Objectives
  • SOC-CY-DC4 Governance Structure

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • AS9100D-8.1 Operational Planning and Control
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware
  • 3.14.3e Include Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs

South Korea ISMS-P · 2 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AMLCTF-82 Part A Compliance
  • SPS220-28 Annual Board Risk Management Declaration
  • ACQS-8-4 Risk Management
  • ACQ.4 Supplier Monitoring
  • Mat 03 Responsible Sourcing of Materials

CIS Controls v8 · 1 control

  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components

EU AI Act · 1 control

  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices

ISO 27001:2022 · 1 control

  • 5.21 Managing information security in the information and communication technology (ICT) supply chain

ISO 27002:2022 · 1 control

  • 5.21 Managing information security in the ICT supply chain
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-50001-8.3 Procurement

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity

NIS2 Directive · 1 control

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring

NIST SP 800-218 · 1 control

  • SR-11 SR-11 Component Authenticity
  • SR-11 SR-11 Component Authenticity
  • SR-11 SR-11 Component Authenticity
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training

PCI DSS 4.0 · 1 control

  • 9.5.1 9.5.1 Protection of POI devices from tampering
  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • 2.7.2 Food Fraud Plan
  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • IM8-TPM.4 Supply Chain Risk Management
  • TSSR-SEC-3 National Security Risk Management
  • CRM-3 Risk Management Framework
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-03 Supply Chain Security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SR - Supply Chain Risk Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-SR-11 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 236 it maps to, and the evidence behind each claim, over MCP and REST.