Frameworks / NIST SP 800-53 Rev 5 / NIST800-SR-3 NIST SP 800-53 Rev 5
SR - Supply Chain Risk Management
NIST SP 800-53 Rev 5 NIST800-SR-3: SR-3 Supply Chain Controls and Processes a. Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Assignment: organization-defined system or system component] in coordination with [Assignment: organization-defined supply chain personnel]; b. Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events: [Assignment: organization-defined supply chain controls]; and c. Document the selected and implemented supply chain processes and controls in [Selection (one or more): security and privacy plans; supply chain risk management plan; [Assignment: organization-defined document]].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 287 controls across 118 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-37 Service Provider Management Policy CPS230-46 Ongoing Risk Management of Each Material Arrangement CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing CPS230-50 Formal Agreement Content for Material Arrangements SASB-1 Business Model + Innovation (BMI) SASB-3 Leadership and Governance (LG) SASB-BMI-3 Supply Chain Management SASB-LG-2 Systemic Risk Management SASB-LG-3 Critical Incident Risk Management SASB-LG-5 Systemic Risk Management AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability AEO-7 Trading Partner Security P1-S2 Risk-Management Systems P2-S1 Partnership CIS-15.1 Establish and Maintain an Inventory of Service Providers CIS-15.4 Ensure Service Provider Contracts Include Security Requirements CIS-15.5 Assess Service Providers CIS-15.6 Monitor Service Providers CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components 27557-1 Scope 27557-3 Terms and definitions 27557-6.4 Privacy risk treatment 27557-6.6 Recording and reporting 27557-7.3 Risk-based privacy program implementation API1164-16 Supply Chain and Third Party API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures ISO-20400-4.5 Key considerations for sustainable procurement ISO-20400-7.3 Supplier selection ISO-20400-7.4 Contract management and review ISO-20400-7.5 Reviewing and learning 5.19 Information security in supplier relationships 5.20 Addressing information security within supplier agreements 5.21 Managing information security in the information and communication technology (ICT) supply chain 5.22 Monitoring, review and change management of supplier services 5.19 Information security in supplier relationships 5.20 Addressing information security within supplier agreements 5.21 Managing information security in the ICT supply chain 5.22 Monitoring, review and change management of supplier services 6.12.1 Information security in supplier relationships 6.12.2 Supplier service delivery management 7.2.6 Contracts with PII processors 8.5.7 Engagement of a subcontractor to process PII ISO23894-5.1 Leadership and Commitment ISO23894-5.2 AI Risk Management Integration ISO23894-5.5 Framework Evaluation ISO23894-A.6 AI System Security ISO27003-4.2 Understanding the needs and expectations of interested parties ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.1 Operational planning and control ISO27003-8.3 Information security risk treatment ISO27019-21 Supply chain risk management for critical components ISO27019-22 Configuration management for OT systems ISO27019-23 Change management procedures ISO27019-24 Vulnerability assessment for critical systems SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SOCI-S30AC Obligation to adopt a CIRMP SOCI-S30AD Compliance with CIRMP SOCI-S30AE Annual review of CIRMP SII-P2-09 Outsourcing Requirements SII-P2-11 Remuneration Policy SII-P2-12 Written Policies SII-P3-06 SFCR Section B: System of Governance CPS234-16 Assessment of Related Party and Third Party Capability CPS234-20 Information Asset Classification CPS234-P22 Evaluation of Third Party Control Design IS.D.OR.210 Information Security Risk Treatment IS.I.OR.210 Information Security Risk Treatment IS.I.OR.220 Information Security Risk Management FFIEC-03 Risk appetite and tolerance for IT risk FFIEC-18 Ongoing monitoring and assessment FFIEC-20 Exit strategy and transition planning RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1)) SR-3 Supply Chain Controls and Processes (SR-3) SR-5 Acquisition Strategies, Tools, and Methods (SR-5) RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1)) SR-3 Supply Chain Controls and Processes (SR-3) SR-5 Acquisition Strategies, Tools, and Methods (SR-5) 60601-1.4.1 General requirements 60601-1.4.2 Risk management process 60601-1.5.1 General requirements for testing IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning IEC62304-7.4 Risk Management of Software Changes IEC62443-21 Supply chain risk management for critical components IEC62443-22 Configuration management for OT systems IEC62443-23 Change management procedures A.1 Point-of-Care Testing Additional Requirements ISO-15189-5.6 Risk management ISO-15189-6.8 Externally provided products and services ISO28001-PC-03 Supply Chain Incident Reporting ISO28001-PC-04 Supply Chain Continuity Planning ISO28001-SA-04 Security Risk Treatment Planning 12.8.1 12.8.1 List of third-party service providers 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs PCI-P2PE-16 Due diligence and onboarding PCI-P2PE-18 Ongoing monitoring and assessment PCI-P2PE-19 Concentration risk management PCI-PIN-16 Due diligence and onboarding PCI-PIN-18 Ongoing monitoring and assessment PCI-PIN-19 Concentration risk management PCI-SSF-03 Risk appetite and tolerance for IT risk PCI-SSF-16 Due diligence and onboarding PCI-SSF-17 Contractual security requirements RMI-DD-3 Red Flag Review RMI-MS-2 Cobalt Standard RMI-RMAP-2 Risk-Based Audit Approach SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures SOC-CY-DC1 Nature of Business and Operations SOC-CY-DC3 Cybersecurity Risk Management Objectives SOC-CY-DC4 Governance Structure AS9100D-8.1 Operational Planning and Control AS9100D-8.4 Control of Externally Provided Processes, Products, Services ASBv3-DS-3 Secure DevOps infrastructure DS-2 Ensure software supply chain security BS65000-RM-01 Resilience Journey BS65000-RM-02 Integrated Approach C5-SSO-02 Risk assessment of service providers and suppliers C5-SSO-04 Monitoring of compliance with requirements CPG-6.A Vendor and Supplier Incident Reporting CPG-6.B Supply Chain Incident Reporting DORA-Art.28 ICT third-party risk: general principles DORA-Art.29 Preliminary assessment of ICT concentration risk at entity level CAT-D1-2 Risk management CAT-ML-2 Evolving ICP-16 Enterprise Risk Management for Solvency Purposes ICP-8 Risk Management and Internal Controls ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OSFIB13-4 Third-Party Risk Management and Cloud PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs ISMSP-MS-02 Risk Management ISMSP-PI-03 Third-Party Provision and Outsourcing CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records AMLCTF-82 Part A Compliance ANSSI-HYG-03 Control the Risks of Outsourced Information System Management SPS220-28 Annual Board Risk Management Declaration SEC11-BP05 Centralize services for packages and dependencies ACQ.4 Supplier Monitoring Mat 03 Responsible Sourcing of Materials CFTC-SS-30 Outsourcing with Retention of Complete Responsibility ZTMM-DEV-SCRM Devices Pillar: Asset and Supply Chain Risk Management CJIS-19 Supply Chain Risk Management Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) ISO22316-14 Supply chain continuity ISO-22320-4.3 Risk-based approach ISO-26000-6.6 Fair operating practices ISO-41001-8.4 Control of outsourced processes and services ISO-50001-8.3 Procurement 27010-15.1 Incident Management 27011-5.6 Supplier relationships and telecom supply chain ISO22317-14 Supply chain continuity ISO22318-14 Supply chain continuity Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring 03.17.03 Supply Chain Requirements and Processes 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring SR-3 SR-3 Supply Chain Controls and Processes SR-3 SR-3 Supply Chain Controls and Processes SR-3 SR-3 Supply Chain Controls and Processes 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard) NZISM-1 NZISM Governance, Documentation, and Classification System ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture OECDMNE-5 Environment, Climate, and Biodiversity OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework PASONE-3 Personnel Security, Vetting, Awareness, and Training PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement SECCLIM-2 Risk Management: Identification, Assessment, Integration SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management AIGF-1.1 Risk Management and Internal Controls IM8-TPM.4 Supply Chain Risk Management GT-3 Supply Chain Compromise TSSR-SEC-3 National Security Risk Management CRM-3 Risk Management Framework UKAI-1 Risk-Based Approach and Pro-Innovation Principles UKOPRES-5 Third-Party Risk, Concentration Risk UKGAMBLE-4 Resilience and Incident Response SEMD-PS-3 Supply Chain Security UK-TSA-NET-03 Supply Chain Security Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SR - Supply Chain Risk Management You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-SR-3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 287 it maps to, and the evidence behind each claim, over MCP and REST.