STIGhub
STIGs
RMF Controls
Compare
← All Controls
SR-1
Supply Chain Risk Management
Rev 5
Policy and Procedures
CCI Identifiers (16)
CCI-005056
Disseminate an organization-level, mission/business process-level, and/or system-level supply chain risk management policy to organization-defined personnel or roles.
CCI-005057
Develop and document an organization-level, mission/business process-level, and/or system-level supply chain risk management policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-005058
Develop and document organization-level, mission/business process-level, and/or system-level supply chain risk management policy that is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
CCI-005059
Develop and document procedures to facilitate the implementation of the supply chain risk management policy and the associated supply chain risk management controls.
CCI-005060
Designate an organization-defined official to manage the development and documentation of the supply chain risk management policy.
CCI-005061
Designate an organization-defined official to manage the development and documentation of the supply chain risk management procedures.
CCI-005062
Designate an organization-defined official to manage the dissemination of the supply chain risk management policy.
CCI-005063
Designate an organization-defined official to manage the dissemination of the supply chain risk management procedures.
CCI-005064
Review and update the current supply chain risk management policy on an organization-defined frequency.
CCI-005065
Defines the frequency for reviewing and updating the current supply chain risk management policy.
CCI-005066
Review and update the current supply chain risk management policy following organization-defined events.
CCI-005067
Defines the events following reviewing and updating the current supply chain risk management policy.
CCI-005068
Review and update the current supply chain risk management procedures on an organization-defined frequency.
CCI-005069
Defines the frequency for reviewing and updating the current supply chain risk management procedures.
CCI-005070
Review and update the current supply chain risk management procedures following organization-defined events.
CCI-005071
Defines the events following reviewing and updating the current supply chain risk management procedures.
Linked STIG Checks (0)
No STIG checks reference this control.