Supply Chain Risk Management Plan
Documents how supply-chain risk is identified, assessed, and mitigated across the system's lifecycle. Covers SCRM plan governance, processes for managing supply-chain risk, acquisition strategies that select trustworthy suppliers, supplier assessments and reviews, notification agreements, inspection of received components, anti-counterfeit / authenticity controls, and component disposal. Covers the controls of the SR family in NIST SP 800-53 r5 and aligns with NIST SP 800-161 r1 (Cybersecurity Supply Chain Risk Management Practices), NIST SP 800-53A r5 (Assessment), Executive Order 14028, OMB M-22-18 / M-23-16 (software supply chain), Section 889 of the FY2019 NDAA (covered telecommunications), CISA ICT-SCRM Task Force guidance, and FedRAMP Continuous Monitoring requirements.