CMMC v2.11 Practices

RA.L3-3.11.7e  

Reference: CMMC v2.11

Family: RA

Level Introduced: 3

Title: Supply Chain Risk Plan

Practice:
Develop a plan for managing supply chain risks associated with organizational systems and system components; update the plan at least annually, and upon receipt of relevant cyber threat information, or in response to a relevant cyber incident.

Further Discussion:
An organization is required to have a supply chain risk management plan that assesses and responds to the identified risks from those organizations that provide IT products or services, including any cloud or other third-party services with a role in the operation of the system. The organization should be cognizant of services outside the scope of the system but required for the operation of the system as part of their plan. Since the cyber environment changes rapidly and continuously, it is equally important for the organization to update the plan in response to supply chain cyber incidents or emerging information.

Example
You are responsible for information security in your organization, and you have created a supply chain risk management plan [a,b,c]. One of the organization’s suppliers determines that it has been the victim of a cyberattack. Your security team meets with the supplier to determine the nature of the attack and to understand the adversary, the attack, the potential for corruption of delivered goods or services, and current as well as future risks. The understanding of the supply chain will help protect the local environment. Subsequently, you update the risk management plan to include a description of the necessary configuration changes or upgrades to monitoring tools to improve the ability to identify the new risks, and when improved tools are available, you document the acquisition of defensive tools and associated functionality to help mitigate any of the identified techniques [d].

Potential Assessment Considerations
• Does the organization’s current supply chain risk management plan apply across the enterprise, or does it only apply to a limited portion of the supply chain [b]?

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

Source: CMMC v2.11