FedRAMP Controls / SR
SR-6 Supplier Assessments and Reviews
Family SR
Baselines moderate
Mapped KSIs 2
Control statement
Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide {{ insert: param, sr-06_odp }}.
Requirement: CSOs must ensure that their supply chain vendors build and test their systems in alignment with NIST SP 800-171 or a commensurate security and compliance framework. CSOs must ensure that vendors are compliant with physical facility access and logical access controls to supplied products. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-TPR-03 | Supply Chain Risk Management _Persistently_ identify, review, and mitigate potential supply chain risks. | Third-Party Information Resources |
| KSI-TPR-04 | Supply Chain Risk Monitoring Automatically monitor third party software _information resources_ for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services. | Third-Party Information Resources |