|
controlSR-11
Component Authenticity (SR-11)
Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and Report counterfeit system components to [organization-defined].
Security Baselines
LOWMODERATEHIGH
supply-chainacquisitionthird-partyrisk
Why These Connect
Maps To2
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports26
These related controls work together — a change to one may affect the others.
Enhances3
These enhancements add specific capabilities or refinements to the base control.
Related Controls(14)
AT-3Role-based Training (AT-3)
LMH
CM-3Configuration Change Control (CM-3)MH
MA-2Controlled Maintenance (MA-2)LMH
MP-6Media Sanitization (MP-6)LMH
PM-30Supply Chain Risk Management Strategy (PM-30)RA-5Vulnerability Monitoring and Scanning (RA-5)LMH
SA-24Design For Cyber Resiliency (SA-24)SI-7Software, Firmware, and Information Integrity (SI-7)MH
SR-3Supply Chain Controls and Processes (SR-3)LMH
SR-5Acquisition Strategies, Tools, and Methods (SR-5)LMH
SR-9Tamper Resistance and Detection (SR-9)H
SR-10Inspection of Systems or Components (SR-10)LMH
PE-3Physical Access Control (PE-3)LMH
SA-4Acquisition Process (SA-4)LMH
Cross-Framework Mappings(2)
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(3)
SelectionSelection (one-or-more): source of counterfeit component / {{ insert: param, sr-11_odp.02 }} / {{ insert: param, sr-11_odp.03 }}
Assignmentorganization-defined external reporting organizations
Assignmentorganization-defined personnel or roles