Skip to main content

πŸ’Ό SR-6 Supplier Assessments and Reviews (M)(H)

  • Contextual name: πŸ’Ό SR-6 Supplier Assessments and Reviews (M)(H)
  • ID: /frameworks/fedramp-high-security-controls/sr/06
  • Located in: πŸ’Ό Supply Chain Risk Management

Description​

Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide [FedRAMP Assignment: at least annually].

SR-6 Additional FedRAMP Requirements and Guidance:

Requirement: CSOs must ensure that their supply chain vendors build and test their systems in alignment with NIST SP 800-171 or a commensurate security and compliance framework. CSOs must ensure that vendors are compliant with physical facility access and logical access controls to supplied products.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/sr/06
  • Internal
    • ID: dec-c-4516a0a7

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-6 Supplier Assessments and Reviews1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό SR-6 Supplier Assessments and Reviews (M)(H)

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags