IR-04(10) Supply Chain Coordination
Coordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.
Organizations involved in supply chain activities include product developers, system integrators, manufacturers, packagers, assemblers, distributors, vendors, and resellers. Supply chain incidents can occur anywhere through or to the supply chain and include compromises or breaches that involve primary or sub-tier providers, information technology products, system components, development processes or personnel, and distribution processes or warehousing facilities. Organizations consider including processes for protecting and sharing incident information in information exchange agreements and their obligations for reporting incidents to government oversight bodies (e.g., Federal Acquisition Security Council).
Related controls 4
- CA-03 Information Exchange L M H P
- MA-02 Controlled Maintenance L M H P
- SA-09 External System Services L M H P
- SR-08 Notification Agreements L M H P