# SR-6 — Supplier Assessments and Reviews

- **Control ID:** SR-6
- **Family:** [SR](/md/families/SR.md)
- **Baselines:** moderate, high
- **Enhancement of:** No content available.

## Description

Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide \[assignment\].

## Discussion

An assessment and review of supplier risk includes security and supply chain risk management processes, foreign ownership, control or influence (FOCI), and the ability of the supplier to effectively assess subordinate second-tier and third-tier suppliers and contractors. The reviews may be conducted by the organization or by an independent third party. The reviews consider documented processes, documented controls, all-source intelligence, and publicly available information related to the supplier or contractor. Organizations can use open-source information to monitor for indications of stolen information, poor development and quality control practices, information spillage, or counterfeits. In some cases, it may be appropriate or required to share assessment and review results with other organizations in accordance with any applicable rules, policies, or inter-organizational agreements or contracts.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [GV.OC-02](/md/csf/GV.OC-02.md) — Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
- [GV.OV-01](/md/csf/GV.OV-01.md) — Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- [GV.OV-02](/md/csf/GV.OV-02.md) — The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
- [GV.OV-03](/md/csf/GV.OV-03.md) — Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
- [GV.SC-04](/md/csf/GV.SC-04.md) — Suppliers are known and prioritized by criticality
- [GV.SC-05](/md/csf/GV.SC-05.md) — Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
- [GV.SC-06](/md/csf/GV.SC-06.md) — Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
- [GV.SC-07](/md/csf/GV.SC-07.md) — The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
- [GV.SC-09](/md/csf/GV.SC-09.md) — Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
- [GV.SC-10](/md/csf/GV.SC-10.md) — Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
- [ID.RA-09](/md/csf/ID.RA-09.md) — The authenticity and integrity of hardware and software are assessed prior to acquisition and use
- [ID.RA-10](/md/csf/ID.RA-10.md) — Critical suppliers are assessed prior to acquisition

## Related controls

- [SR-3](/md/controls/SR-3.md)
- [SR-5](/md/controls/SR-5.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
