Control Statement
The organization shall maintain a supply chain risk management program meeting its federal obligations, and shall record which acquisitions fall within its scope.
Purpose. To discharge the statutory supply chain risk obligation, and to make the boundary of its scope explicit rather than assumed.
Discussion
The distinction between this control and LC-1 is the difference between an obligation and an operation. LC-1 asks who has a path into the estate and what it reaches — a terrain question, answered on the overlay. FO-6 asks whether the agency runs the program it is required to run, and to which acquisitions that program applies. Scope is where this control does its work: supply chain obligations rarely apply to every acquisition, and an agency that has never recorded the boundary cannot demonstrate either compliance inside it or a considered position outside it.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of suppliers with estate access represented on the overlay
- Number of supplier access paths with no recorded owner
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- Outside the frameworkContract, procurement and vendor access records
- TM-1 Terrain Inventory and OverlayTerrain overlay
Produces
- LC-1 Supplier Terrain RegisterPopulation for the detailed supplier terrain register
- KT-3 Avenue of Approach AnalysisSupplier paths as avenues of approach
- TM-5 Connection and Denied-Path RegisterSupplier connections recorded in the connection register
Activities
- L2Maintain a supply chain risk management program meeting the agency's federal obligations.
- L2Record which acquisitions fall within its scope.
- L2Record the basis on which acquisitions are excluded.
- L3Derive scope from the governing obligations rather than from acquisition value thresholds alone.
- L3Integrate the program's determinations into acquisition decisions before award rather than after.
- L3Reconcile in-scope acquisitions against the supplier terrain register (LC-1), so a supplier with estate access that fell outside SCRM scope is visible as a deliberate position rather than an oversight.
- L3Record prohibited-source and exclusion determinations and the action taken.
- L4Measure the proportion of in-scope acquisitions assessed before award.
- L4Measure the gap between suppliers holding estate access (LC-1) and suppliers within SCRM scope, and treat a large gap as a finding about scope.
- L5Revise scope where the reconciliation with LC-1 repeatedly shows access-holding suppliers falling outside it.
Measurement
Percentage of in-scope acquisitions assessed before award.
Count of access-holding suppliers falling outside SCRM scope.
Evidence and Assessment
SCRM program record with scope and recorded exclusions; pre-award assessments; reconciliation against the supplier terrain register.
Examine the program against the governing obligations; test that in-scope acquisitions were assessed before award; test the reconciliation against LC-1 for access-holding suppliers outside scope.
Related Guidance
- SR-3
- SR-6
- SA-9
- GV.SC-01
- GV.SC-04
- GV.SC-06
- GV.SC-09
- ID.RA-09
- ID.RA-10
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.14
Terrain It Is Named On
- T9Supply ChainSupply chain terrain — the control that requires this ground to be identified as terrain rather than managed as vendor paperwork.
Artifacts It Stands On
- producesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.