{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Secure Configuration & Change Management"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-supply-chain-injection","description":"Adversary creates false-front suppliers or intercepts the supply chain to insert counterfeit or tampered hardware, corrupted software/firmware, or malicious components into products and information systems.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"high","likelihood":"low","risk_id":"tprm-supply-chain-injection","taxonomies":["nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-threat"],"treatment":"mitigate"},"id":"risk:tprm-supply-chain-injection","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-supply-chain-injection","sourceIds":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Malicious supply-chain injection of tampered hardware/software","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0af7cbcc3af62176d9352b1122aa71c17fdd98cc3d7c63eea18c5051b4a245b7","properties":{"rationale":"Supplier notification of supply-chain compromises plus pre-planned coordinated response cuts detection and containment time for injected tampered components.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1ebb00b3f0dd3045b31612052817526c50fe9eaa2243a3c69bd3fe401bba60d0","properties":{"rationale":"Inspecting maintenance tools/media for tampering blocks one narrow injection vector, but broad authenticity/integrity verification of acquired hardware and software (UC-CONFIG-06) is the operative supply-chain-injection defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3e9ca7b20a119c026f20a2591ab51cd6f9d1f86934f861a15d02defca5b7ce28","properties":{"rationale":"Provenance and BOM records, chain-of-custody, tamper-evident packaging, receipt inspection, and authenticity verification directly detect counterfeit and tampered hardware and components.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:510361a83a227b7700820d4364fcf8eea9d9b142aa01b5d0753ec9e7c3981c4b","properties":{"rationale":"Protected dependency baselines and configuration-integrity verification help detect tampered or counterfeit components.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:733d2d5f37ca5636a2c55417459ef204bce8eb39dae38ceeac518e75ae1cef80","properties":{"rationale":"Acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before award defend against false-front and compromised suppliers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8bc84b54a9a5b7f2570770fd68a2241f8d328291858b704db7324545dfb5904b","properties":{"rationale":"Screening developers of critical systems and reviewing deliverables reduces malicious insertion via outsourced development.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-10-3ac58852.json","sourceId":"uc:UC-SDLC-10","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfe844ecfbcdc47bce29a95ee1844b0b24dd01c513f4494033f5812b8dea014c","properties":{"rationale":"Verifying digital signatures/integrity and sourcing from trusted suppliers before use directly blocks tampered or counterfeit hardware and software from entering.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","sourceId":"uc:UC-CONFIG-06","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e765571a8e4ff68f52862f3ba7a0920f9e38f78855b7c362d2b12fe203ff7259","properties":{"rationale":"Protecting sensitive info on suppliers, shipments, configurations, and delivery schedules from adversary collection denies the intelligence needed to intercept and inject into the supply chain.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-09-eb9772d0.json","sourceId":"uc:UC-TPRM-09","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edf7c481fd614b92be79dfc69f09750b963d40c5080104996dad923baae16327","properties":{"rationale":"Custom/specialized reimplementation of critical components explicitly reduces supply-chain injection of tampered third-party parts.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","sourceId":"uc:UC-SDLC-11","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"}],"schemaVersion":1}
