SR-11 Component Authenticity
Supply Chain Risk Management
Description
a. Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and b. Report counterfeit system components to [Selection (one or more): source of counterfeit component; [Assignment: organization-defined external reporting organizations]; [Assignment: organization-defined personnel or roles]].
Supplemental Guidance
Sources of counterfeit components include manufacturers, developers, vendors, and contractors. Anti-counterfeiting policies and procedures support tamper resistance and provide a level of protection against the introduction of malicious code. External reporting organizations include CISA.
Changes from Rev 4
New control family introduced in Rev 5
Enhancements (3)
What NIST adds to this control. Select one to read its statement.
SR-11(01) Anti-counterfeit Training LowModerateHigh
Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware).
SR-11(02) Configuration Control for Component Service and Repair LowModerateHigh
Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system components].
SR-11(03) Anti-counterfeit Scanning
Scan for counterfeit system components [Assignment: organization-defined frequency].
MITRE ATT&CK Techniques (15)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.