{"data":{"id":"SR-10","name":"Inspection of Systems or Components","family":"SR","family_name":"Supply Chain Risk Management","withdrawn":false,"description":"Inspect the following systems or system components [Selection (one or more): at random; at [Assignment: organization-defined frequency], upon [Assignment: organization-defined indications of need for inspection]] to detect tampering: [Assignment: organization-defined systems or system components].","supplemental_guidance":"The inspection of systems or systems components for tamper resistance and detection addresses physical and logical tampering and is applied to systems and system components removed from organization-controlled areas. Indications of a need for inspection include changes in packaging, specifications, factory location, or entity in which the part is purchased, and when individuals return from travel to high-risk locations.","enhancements":[],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SR-10","name":"Inspection of Systems or Components","description":"Inspect the following systems or system components [Selection (one or more): at random; at [Assignment: organization-defined frequency], upon [Assignment: organization-defined indications of need for inspection]] to detect tampering: [Assignment: organization-defined systems or system components].","discussion":"The inspection of systems or systems components for tamper resistance and detection addresses physical and logical tampering and is applied to systems and system components removed from organization-controlled areas. Indications of a need for inspection include changes in packaging, specifications, factory location, or entity in which the part is purchased, and when individuals return from travel to high-risk locations.","related_controls":["AT-03","PM-30","SI-04","SI-07","SR-03","SR-04","SR-05","SR-09","SR-11"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":true,"changes_from_rev4":"New control family introduced in Rev 5"}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["5.21"],"cobit_2019":[],"pci_dss_v4":["9.5"],"nist_csf_2":["GV.SC-05","ID.RA-09"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.6.2.4"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.31","Hygiene.42","SecNumCloud.16.2"],"osfi_b13":["B-13.4.1"],"finma_circular":["VII.A(113)","VII.B(114)"],"gdpr":["Art.28(3)(h)"],"dora":["Art.28(6)"],"bio2":["5.21"],"rbi_csf":["Annex1.18"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-15"],"uae_ia":["T10"],"ffiec_is":["II.C.14"],"iosco_cyber":["PROT-7"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":["Sec 6"],"pci_pts":["A","G","I"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":["2"],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.9.3"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":["MS8.8"],"naic_ds":[],"nhs_dspt":["NDG-10.4"],"pra_ss1_23":[],"solvency_ii":["Art.49(2)","DR.272","EIOPA-Cloud-GL7"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.54"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 GV.SC-05 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: statement, discussion and related controls taken from NIST SP 800-53 Release 5.2.0, which this file lacked.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-031","SP-034","SP-036"]}}