CCI-005089
      
        
        
      
      
        
  CCI-005089 Definition
      
      
        
        
      
    
  | Status | |
| Type | CheckType.technical | 
      
        
        
      
      
        
  Master Assessment Datasheet
      
      
        
        
      
    
  Implementation Guidance
Determine if the selected and implemented supply chain processes and controls are documented in [SR-03_ODP[04]; one or more of the following PARAMETER VALUES is/are selected: {security and privacy plans; supply chain risk management plan; [SR-03_ODP[05]; the document identifying the selected and implemented supply chain processes and controls is defined (if selected)]}].
Validation Procedures
Examine: [SELECT FROM: Supply chain risk management policy; supply chain risk management procedures; supply chain risk management strategy; supply chain risk management plan; systems and critical system components inventory documentation; system and services acquisition policy; system and services acquisition procedures; procedures addressing the integration of information security and privacy requirements into the acquisition process; solicitation documentation; acquisition documentation (including purchase orders); service level agreements; acquisition contracts for systems or services; risk register documentation; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with acquisition responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel with supply chain risk management responsibilities]. Test: [SELECT FROM: Organizational processes for identifying and addressing supply chain element and process deficiencies].