Skip to content

SR-6: Supplier Assessments and Reviews

An OSCAL Control

Statement

    • Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide .

        • Requirement:

          CSOs must ensure that their supply chain vendors build and test their systems in alignment with NIST SP 800-171 or a commensurate security and compliance framework. CSOs must ensure that vendors are compliant with physical facility access and logical access controls to supplied products.