unified

UC-TPRM-07 — Verify component authenticity, provenance, and integrity

Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Third-Party / Supply-Chain Risk
type
preventive
category
administrative

Details

unified_id
UC-TPRM-07
title
Verify component authenticity, provenance, and integrity
statement
Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.
domain
Third-Party / Supply-Chain Risk
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    SR-4
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SR-9
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SR-10
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SR-11
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.5.21
    coverage
    partial
    delta
    propagation of security requirements through the ICT supply chain via contract control
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections