CCI-005140
CCI-005140 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - configuration control over [SR-11(02)_ODP; system components requiring configuration control are defined] awaiting service or repair is maintained. - configuration control over serviced or repaired [SR-11(02)_ODP; system components requiring configuration control are defined] awaiting return to service is maintained.
Validation Procedures
Examine: [SELECT FROM: Supply chain risk management policy and procedures; supply chain risk management plan; configuration control procedures; acquisition documentation; service level agreements; acquisition contracts for the system component; inter-organizational agreements and procedures; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system and services acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with supply chain risk management responsibilities]. Test: [SELECT FROM: Organizational processes for establishing inter-organizational agreements and procedures with supply chain entities; organizational configuration control processes].