# SR-07 Supply Chain Operations Security

NIST SP 800-53 control. Family: SR Supply Chain Risk Management. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: [Assignment: organization-defined Operations Security (OPSEC) controls].
Guidance: Supply chain OPSEC expands the scope of OPSEC to include suppliers and potential suppliers. OPSEC is a process that includes identifying critical information, analyzing friendly actions related to operations and other activities to identify actions that can be observed by potential adversaries, determining indicators that potential adversaries might obtain that could be interpreted or pieced together to derive information in sufficient time to cause harm to organizations, implementing safeguards or countermeasures to eliminate or reduce exploitable vulnerabilities and risk to an acceptable level, and considering how aggregated information may expose users or specific uses of the supply chain. Supply chain information includes user identities; uses for systems, system components, and system services; supplier identities; security and privacy requirements; system and component configurations; supplier processes; design specifications; and testing and evaluation results. Supply chain OPSEC may require organizations to withhold mission or business information from suppliers and may include the use of intermediaries to hide the end use or users of systems, system components, or system services.

## Clauses by framework (16 frameworks)
- iso_27001_2022: A.5.22
- soc2_tsc: CC2.2, CC3.1, CC3.2, CC4.1, CC9.2, CC9.2-POF1
- iso_42001_2023: A.10.3
- anssi: Hygiene.42, SecNumCloud.16.1
- osfi_b13: B-13.4.1
- gdpr: Art.28(3)(a), Art.28(3)(h)
- dora: Art.28(5), Art.30(2)(a)
- rbi_csf: Annex1.11
- cbb_tm: TM-15
- bot_cyber: Ch5.1
- ffiec_is: II.A.1, II.C.14
- iosco_cyber: PROT-7
- isae_3402: Clause 8
- fca_sysc_13: SYSC 13.9.2
- solvency_ii: DR.272
- basel_sco60: SCO60.54
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SR-07
- Clauses only: /api/v1/controls/SR-07?fields=mappings
- Page for people: /controls/sr-07/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
