unified
UC-TPRM-07 — Verify component authenticity, provenance, and integrity
Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-TPRM-07
- title
- Verify component authenticity, provenance, and integrity
- statement
- Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SR-4
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-9
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-10
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-11
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.21
- coverage
- partial
- delta
- propagation of security requirements through the ICT supply chain via contract control
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-9 — Tamper Resistance and Detection
- framework
- nist-800-53
- control_id
- SR-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-11 — Component Authenticity
- framework
- nist-800-53
- control_id
- SR-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-4 — Provenance
- framework
- nist-800-53
- control_id
- SR-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Provenance and BOM records, chain-of-custody, tamper-evident packaging, receipt inspection, and authenticity verification directly detect counterfeit and tampered hardware and components.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to A.5.21 — Managing information security in the ICT supply chain
- framework
- iso-27001
- control_id
- A.5.21
- coverage
- partial
- delta
- propagation of security requirements through the ICT supply chain via contract control
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-10 — Inspection of Systems or Components
- framework
- nist-800-53
- control_id
- SR-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- Supply-Chain Integrity & OPSEC Operations operates UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Maintaining provenance and verifying integrity of components and data catches backdoored or malicious third-party libraries and models.