{"data":{"id":"SR-06","name":"Supplier Assessments and Reviews","family":"SR","family_name":"Supply Chain Risk Management","withdrawn":false,"description":"Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide [Assignment: organization-defined frequency].","supplemental_guidance":"An assessment and review of supplier risk includes security and supply chain risk management processes, foreign ownership, control or influence (FOCI), and the ability of the supplier to effectively assess subordinate second-tier and third-tier suppliers and contractors. The reviews may be conducted by the organization or by an independent third party. The reviews consider documented processes, documented controls, all-source intelligence, and publicly available information related to the supplier or contractor. Organizations can use open-source information to monitor for indications of stolen information, poor development and quality control practices, information spillage, or counterfeits. In some cases, it may be appropriate or required to share assessment and review results with other organizations in accordance with any applicable rules, policies, or inter-organizational agreements or contracts.","enhancements":[{"id":"SR-06(01)","name":"Testing and Analysis","statement":"Employ [Selection (one or more): organizational analysis; independent third-party analysis; organizational testing; independent third-party testing] of the following supply chain elements, processes, and actors associated with the system, system component, or system service: [Assignment: organization-defined supply chain elements, processes, and actors].","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SR-06","name":"Supplier Assessments and Reviews","description":"Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide [Assignment: organization-defined frequency].","discussion":"An assessment and review of supplier risk includes security and supply chain risk management processes, foreign ownership, control or influence (FOCI), and the ability of the supplier to effectively assess subordinate second-tier and third-tier suppliers and contractors. The reviews may be conducted by the organization or by an independent third party. The reviews consider documented processes, documented controls, all-source intelligence, and publicly available information related to the supplier or contractor. Organizations can use open-source information to monitor for indications of stolen information, poor development and quality control practices, information spillage, or counterfeits. In some cases, it may be appropriate or required to share assessment and review results with other organizations in accordance with any applicable rules, policies, or inter-organizational agreements or contracts.","related_controls":["SR-03","SR-05"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":true,"changes_from_rev4":"New control family introduced in Rev 5"}},"compliance_mappings":{"iso_27001_2022":["A.5.21","A.5.22"],"iso_27002_2022":["5.21","5.22"],"cobit_2019":["APO10"],"pci_dss_v4":["12.8"],"nist_csf_2":["DE.CM-06","GV.OC-02","GV.OV-01","GV.OV-02","GV.OV-03","GV.SC-04","GV.SC-05","GV.SC-06","GV.SC-07","GV.SC-09","GV.SC-10","ID.AM-04","ID.RA-09","ID.RA-10"],"cis_controls_v8":["CIS 15","CIS 15.5","CIS 15.6"],"soc2_tsc":["CC1.4-POF2","CC1.4-POF3","CC3.4","CC9.1","CC9.2-POF13"],"finos_ccc":[],"iso_42001_2023":["A.10.3"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(d)"],"apra_cps_234":["Para 29-33"],"mas_trm":["16"],"pra_op_resilience":["SS2/21-5.1","SS2/21-6.1","SS2/21-6.2","SS2/21-7.1"],"bsi_grundschutz":[],"anssi":["Hygiene.31","Hygiene.42","SecNumCloud.16.2"],"osfi_b13":["B-13.4.1"],"finma_circular":["VII.A(113)","VII.B(114)"],"gdpr":["Art.28(3)(h)"],"dora":["Art.28(6)","Art.30(3)"],"bio2":["5.21","5.22"],"rbi_csf":["Annex1.11"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":["8.1.9.7","8.1.10.12"],"dnb_good_practice":["DNB.14.2","DNB.16.3"],"cra":["CRA.I.2a"],"swift_cscf":["SWIFT.2.8"],"cbb_tm":["TM-15"],"cbuae":["CR-12"],"nca_ecc":["4-1"],"qatar_nia":["SD"],"sama_csf":["4.1","4.2","4.3"],"uae_ia":["T10"],"bog_cisd":["CISD-XVI"],"bom_ctrm":["3.9"],"cbe_csf":["OVM-1"],"cbn_csf":["Part2.4"],"sa_js2":["JS2-8.7"],"bot_cyber":["Ch5.1"],"cpmi_pfmi":["CG.ID","CG.SA"],"eba_ict":["3.2.3"],"ecb_croe":["CROE.2.2.3","CROE.2.7.1"],"ffiec_is":["II.C.14","II.C.20"],"iosco_cyber":["GOV-5","PROT-7","TEST-4"],"nydfs_500":["500.11"],"sebi_cscrf":["GV.SC","PR.CS"],"nerc_cip":["CIP-013-2"],"nrc_73_54":["RG5.71-C-SR"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":["Order 829","Order 850"],"doe_c2m2":["THIRD"],"api_1164":["Sec 12"],"awia":["AWWA Sec 7"],"iaea_nss":["Sec 6"],"pci_pts":["G"],"fips_140":[],"cbest":["CBEST.8"],"tiber_eu":["TIBER.PROV"],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 7"],"fca_sysc_13":["SYSC 13.9.1","SYSC 13.9.2","SYSC 13.9.3"],"fda_21_cfr_11":[],"fda_cyber":["SBOM-3"],"hitrust_csf":["05.b"],"iso_27799":["15.1","15.2"],"lloyds_ms":["MS8.8","MS13.1"],"naic_ds":["4D"],"nhs_dspt":["NDG-10.1","NDG-10.4"],"pra_ss1_23":[],"solvency_ii":["Art.49(1)","Art.49(2)","DR.272","EIOPA-Cloud-GL3","EIOPA-Cloud-GL7"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":["Art.66(1)","Art.66(3)"],"basel_sco60":["SCO60.41","SCO60.54","SCO60.83"],"bssc":["TIS-02"],"sec_custody_digital":["SEC-CD-10"],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 GV.OC-02, GV.OV-01, GV.OV-02, GV.OV-03, GV.SC-05, GV.SC-10, ID.RA-09 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: statement, discussion and related controls taken from NIST SP 800-53 Release 5.2.0, which this file lacked.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-042"]}}