# SR-8 — Notification Agreements

- **Control ID:** SR-8
- **Family:** [SR](/md/families/SR.md)
- **Baselines:** low, moderate, high
- **Enhancement of:** No content available.

## Description

Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the \[assignment\].

## Discussion

The establishment of agreements and procedures facilitates communications among supply chain entities. Early notification of compromises and potential compromises in the supply chain that can potentially adversely affect or have adversely affected organizational systems or system components is essential for organizations to effectively respond to such incidents. The results of assessments or audits may include open-source information that contributed to a decision or result and could be used to help the supply chain entity resolve a concern or improve its processes.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [GV.OC-02](/md/csf/GV.OC-02.md) — Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
- [GV.SC-08](/md/csf/GV.SC-08.md) — Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
- [RC.CO-03](/md/csf/RC.CO-03.md) — Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
- [RS.CO-02](/md/csf/RS.CO-02.md) — Internal and external stakeholders are notified of incidents
- [RS.CO-03](/md/csf/RS.CO-03.md) — Information is shared with designated internal and external stakeholders
- [RS.MA-01](/md/csf/RS.MA-01.md) — The incident response plan is executed in coordination with relevant third parties once an incident is declared

## Related controls

- [IR-4](/md/controls/IR-4.md)
- [IR-6](/md/controls/IR-6.md)
- [IR-8](/md/controls/IR-8.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
