{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-07","description":"Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SR-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SR-9","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SR-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SR-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.21","coverage":"partial","delta":"propagation of security requirements through the ICT supply chain via contract control","framework":"iso-27001","relationship":"intersects_with"}],"statement":"Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.","title":"Verify component authenticity, provenance, and integrity","unified_id":"UC-TPRM-07"},"id":"uc:UC-TPRM-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-07","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-TPRM-07 — Verify component authenticity, provenance, and integrity","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02d3e7adf641319860b07dede410d11d20d1a50eaf4b8c6e3d2a4d7d279a6b30","properties":{"control_id":"SR-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-9-4c9a21e3.json","targetId":"ctrl:nist-800-53:SR-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0f44e869185bcce337dc18ed47d491a14b875d2f809fb33664210e9259867ed6","properties":{"control_id":"SR-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-11-1979816d.json","targetId":"ctrl:nist-800-53:SR-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1fae65c96d52e5538475323881b4ec2d268cadcc4f1d4efd6d7c5df410496b8c","properties":{"control_id":"SR-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-4-b9338df3.json","targetId":"ctrl:nist-800-53:SR-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3e9ca7b20a119c026f20a2591ab51cd6f9d1f86934f861a15d02defca5b7ce28","properties":{"rationale":"Provenance and BOM records, chain-of-custody, tamper-evident packaging, receipt inspection, and authenticity verification directly detect counterfeit and tampered hardware and components.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b20e41bec7d4f4d8d7613344316f1c36b11efb9a68ae6b18216a95d1be1811b","properties":{"control_id":"A.5.21","coverage":"partial","delta":"propagation of security requirements through the ICT supply chain via contract control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-21-40b0d925.json","targetId":"ctrl:iso-27001:A.5.21","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:69b923e83ca68b983e163a98ce613811965226d554d4a187b0f904f85991e5d0","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","targetId":"uc:UC-TPRM-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8899e0390d39d2301ee4345d506a7cc2c98a1e915fa755aa8b4cb1b7d71a7222","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","targetId":"uc:UC-TPRM-07","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8bf2bba4a9e382ac6d6b861b0fa0880a882cb746102bd3319815d13f04d1fc6a","properties":{"control_id":"SR-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-10-3ac84b4f.json","targetId":"ctrl:nist-800-53:SR-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2605157c67e6352d6f18f05b382101580621dee529ab1333e58b5fd6f62e859","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","targetId":"uc:UC-TPRM-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e9bcf6f06bb517f3f7d07073bf3502c0bb1a581b41df0fd29e61f632524f7f8a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c60-62941eb6.json","sourceId":"wf:C60","targetDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","targetId":"uc:UC-TPRM-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f6324bda249867c4d76237fbf840618741b03d0c45baa86c79ab49d905d785d6","properties":{"rationale":"Maintaining provenance and verifying integrity of components and data catches backdoored or malicious third-party libraries and models.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"}],"schemaVersion":1}
