Skip to main content

πŸ’Ό SR-8 Notification Agreements (L)(M)(H)

  • Contextual name: πŸ’Ό SR-8 Notification Agreements (L)(M)(H)
  • ID: /frameworks/fedramp-low-security-controls/sr/08
  • Located in: πŸ’Ό Supply Chain Risk Management

Description​

Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [FedRAMP Assignment: notification of supply chain compromises and results of assessment or audits].

SR-8 Additional FedRAMP Requirements and Guidance:

Requirement: CSOs must ensure and document how they receive notifications from their supply chain vendor of newly discovered vulnerabilities including zero-day vulnerabilities.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/sr/08
    • /frameworks/fedramp-high-security-controls/sr/08
  • Internal
    • ID: dec-c-032b0601

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό SR-8 Notification Agreements (L)(M)(H)
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-8 Notification Agreements

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags