{"data":{"id":"SR-11","name":"Component Authenticity","family":"SR","family_name":"Supply Chain Risk Management","withdrawn":false,"description":"a. Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and\nb. Report counterfeit system components to [Selection (one or more): source of counterfeit component; [Assignment: organization-defined external reporting organizations]; [Assignment: organization-defined personnel or roles]].","supplemental_guidance":"Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include CISA.","enhancements":[{"id":"SR-11(01)","name":"Anti-counterfeit Training","statement":"Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware).","baselines":["low","moderate","high"]},{"id":"SR-11(02)","name":"Configuration Control for Component Service and Repair","statement":"Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system components].","baselines":["low","moderate","high"]},{"id":"SR-11(03)","name":"Anti-counterfeit Scanning","statement":"Scan for counterfeit system components [Assignment: organization-defined frequency].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SR-11","name":"Component Authenticity","description":"a. Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and\nb. Report counterfeit system components to [Selection (one or more): source of counterfeit component; [Assignment: organization-defined external reporting organizations]; [Assignment: organization-defined personnel or roles]].","discussion":"Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include CISA.","related_controls":["PE-03","SA-04","SI-07","SR-09","SR-10"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":true,"changes_from_rev4":"New control family introduced in Rev 5"}},"compliance_mappings":{"iso_27001_2022":["A.5.21"],"iso_27002_2022":["5.21"],"cobit_2019":[],"pci_dss_v4":["9.5"],"nist_csf_2":["ID.RA-09"],"cis_controls_v8":["CIS 16.5"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.7.5"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.42","SecNumCloud.16.1"],"osfi_b13":["B-13.4.1"],"finma_circular":[],"gdpr":["Art.28(3)(h)","Art.30(2)(d)"],"dora":["Art.28(5)","Art.30(2)(a)"],"bio2":["5.21"],"rbi_csf":["Annex1.6"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-15"],"nca_ecc":["4-1"],"uae_ia":["T10"],"cpmi_pfmi":["CG.PR"],"ffiec_is":["II.C.14"],"iosco_cyber":["PROT-7"],"nerc_cip":["CIP-013-2"],"nrc_73_54":["RG5.71-C-SR"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":["Order 850"],"doe_c2m2":[],"api_1164":["Sec 12"],"awia":[],"iaea_nss":["Sec 6"],"pci_pts":["A","G"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":["2"],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":["15.2","H.3"],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":["NDG-10.4"],"pra_ss1_23":[],"solvency_ii":["DR.272"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":["Art.66(3)"],"basel_sco60":["SCO60.54"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification—through cryptographic signing, secure procurement, and supply chain integrity checks—directly mitigates supply chain compromise by detecting tampered or counterfeit components before deployment."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification ensures that server software components—including web server modules and database extensions—are genuine and unmodified, detecting adversary-planted persistent backdoors."},{"id":"T1554","name":"Compromise Host Software Binary","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticity verification of host software binaries through hash validation and code-signing checks detects when adversaries replace or patch legitimate executables with trojaned versions for persistence."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification detects modified system images on network devices by comparing firmware and OS images against vendor-provided cryptographic hashes, identifying adversary-modified boot images."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authenticity verification of AppleScript components through code-signing validation ensures that scripts executed in macOS environments have not been tampered with by adversaries for malicious execution."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification of software dependencies and development tools—through checksum validation and signing—detects compromised build-chain components before they enter the development pipeline."},{"id":"T1195.002","name":"Compromise Software Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticity verification of distributed software through code-signing validation and hash comparison detects compromised software supply chain deliveries where adversaries have modified legitimate packages."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification through hardware attestation, tamper-evident packaging, and supply chain tracking detects counterfeit or modified hardware components introduced during manufacturing or distribution."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authenticity verification of container and VM images through cryptographic signing and hash validation detects malicious images planted in registries, preventing execution of backdoored container workloads."},{"id":"T1505.001","name":"SQL Stored Procedures","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification of SQL stored procedures through integrity checks and change-management controls detects unauthorized database-level code modifications planted for persistence."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticity verification of Exchange transport agents through code-signing and integrity validation detects malicious mail-transport components installed for email interception and persistence."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification of IIS modules and handlers through signing validation detects unauthorized web-server components installed by adversaries for persistent access to web infrastructure."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authenticity verification of Mach-O binaries detects unauthorized LC_LOAD_DYLIB additions by comparing binary load commands against known-good baselines, identifying adversary-modified executables."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component authenticity verification detects patched system images by comparing network device firmware against vendor-published hashes, identifying adversary modifications that alter device behavior for persistence."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authenticity verification detects downgraded system images by validating that network device firmware matches current approved versions, preventing adversary rollback to vulnerable firmware for exploitation."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: statement, discussion and related controls taken from NIST SP 800-53 Release 5.2.0, which this file lacked.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}