Skip to main content

πŸ’Ό SR-2 Supply Chain Risk Management Plan (L)(M)(H)

  • Contextual name: πŸ’Ό SR-2 Supply Chain Risk Management Plan (L)(M)(H)
  • ID: /frameworks/fedramp-high-security-controls/sr/02
  • Located in: πŸ’Ό Supply Chain Risk Management

Description​

a. Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the following systems, system components or system services [Assignment: organization-defined systems, system components, or system services]

b. Review and update the supply chain risk management plan [FedRAMP Assignment: at least annually] or as required, to address threat, organizational or environmental changes; and

c. Protect the supply chain risk management plan from unauthorized disclosure and modification.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/sr/02
  • Internal
    • ID: dec-c-e25d0f35

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan (L)(M)(H)1
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan (L)(M)(H)1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SR-2(1) Establish SCRM Team (L)(M)(H)