← Controls / SR

SR-10 Inspection of Systems or Components

Supply Chain Risk Management

Low Moderate High New in Rev 5

Description

Inspect the following systems or system components [Selection (one or more): at random; at [Assignment: organization-defined frequency], upon [Assignment: organization-defined indications of need for inspection]] to detect tampering: [Assignment: organization-defined systems or system components].

Supplemental Guidance

The inspection of systems or systems components for tamper resistance and detection addresses physical and logical tampering and is applied to systems and system components removed from organization-controlled areas. Indications of a need for inspection include changes in packaging, specifications, factory location, or entity in which the part is purchased, and when individuals return from travel to high-risk locations.

Changes from Rev 4

New control family introduced in Rev 5

Patterns that use this control (3)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27002:2022

5.21

NIST CSF 2.0

GV.SC-05ID.RA-09

PCI DSS v4.0.1

9.5

ISO 42001:2023

A.6.2.4

ANSSI

Hygiene.31Hygiene.42SecNumCloud.16.2

FINMA Circular 2023/1

VII.A(113)VII.B(114)

OSFI B-13

B-13.4.1

EU GDPR

Art.28(3)(h)

EU DORA

Art.28(6)

BIO2

5.21

RBI CSF

Annex1.18

UAE IA

T10

CBB TM

TM-15

IOSCO Cyber Resilience

PROT-7

FFIEC IS

II.C.14

IAEA NSS 17-T

Sec 6

PCI PTS v6

AGI

PCI HSM

2

Solvency II

Art.49(2)DR.272EIOPA-Cloud-GL7

Lloyd's Minimum Standards

MS8.8

FCA SYSC 13

SYSC 13.9.3

NHS DSPT

NDG-10.4

Basel SCO60

SCO60.54