|
controlSR-10
Inspection of Systems or Components (SR-10)
Inspect the following systems or system components [organization-defined] to detect tampering: [organization-defined].
Security Baselines
LOWMODERATEHIGH
supply-chainacquisitionthird-partyrisk
Why These Connect
Maps To4
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports15
These related controls work together — a change to one may affect the others.
Related Controls(10)
SA-24Design For Cyber Resiliency (SA-24)SI-4System Monitoring (SI-4)
LMH
SI-7Software, Firmware, and Information Integrity (SI-7)MH
SR-5Acquisition Strategies, Tools, and Methods (SR-5)LMH
SR-9Tamper Resistance and Detection (SR-9)H
AT-3Role-based Training (AT-3)LMH
PM-30Supply Chain Risk Management Strategy (PM-30)SR-3Supply Chain Controls and Processes (SR-3)LMH
SR-4Provenance (SR-4)SR-11Component Authenticity (SR-11)LMH
Cross-Framework Mappings(4)
GV.SC-05GV.SC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-05GV.SC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(4)
Assignmentorganization-defined systems or system components
SelectionSelection (one-or-more): at random / at {{ insert: param, sr-10_odp.03 }} / upon {{ insert: param, sr-10_odp.04 }}
Assignmentorganization-defined frequency
Assignmentorganization-defined indications of need for inspection