Control statement
Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.
Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-INR-01 | Incident Response Procedures _Persistently_ review the effectiveness of documented incident response procedures. | Incident Response |
| KSI-TPR-04 | Supply Chain Risk Monitoring Automatically monitor third party software _information resources_ for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services. | Third-Party Information Resources |