ASOM-Fedv6.1Open the explorer
FO-6 · Federal Obligations

Supply Chain Obligation

Control Statement

The organization shall maintain a supply chain risk management program meeting its federal obligations, and shall record which acquisitions fall within its scope.

Purpose. To discharge the statutory supply chain risk obligation, and to make the boundary of its scope explicit rather than assumed.

Discussion

The distinction between this control and LC-1 is the difference between an obligation and an operation. LC-1 asks who has a path into the estate and what it reaches — a terrain question, answered on the overlay. FO-6 asks whether the agency runs the program it is required to run, and to which acquisitions that program applies. Scope is where this control does its work: supply chain obligations rarely apply to every acquisition, and an agency that has never recorded the boundary cannot demonstrate either compliance inside it or a considered position outside it.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Suppliers with a path into the estate are represented with their access recorded.
  • Percentage of suppliers with estate access represented on the overlay
  • Number of supplier access paths with no recorded owner

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Maintain a supply chain risk management program meeting the agency's federal obligations.
  2. L2Record which acquisitions fall within its scope.
  3. L2Record the basis on which acquisitions are excluded.
  4. L3Derive scope from the governing obligations rather than from acquisition value thresholds alone.
  5. L3Integrate the program's determinations into acquisition decisions before award rather than after.
  6. L3Reconcile in-scope acquisitions against the supplier terrain register (LC-1), so a supplier with estate access that fell outside SCRM scope is visible as a deliberate position rather than an oversight.
  7. L3Record prohibited-source and exclusion determinations and the action taken.
  8. L4Measure the proportion of in-scope acquisitions assessed before award.
  9. L4Measure the gap between suppliers holding estate access (LC-1) and suppliers within SCRM scope, and treat a large gap as a finding about scope.
  10. L5Revise scope where the reconciliation with LC-1 repeatedly shows access-holding suppliers falling outside it.

Measurement

Outcome

Percentage of in-scope acquisitions assessed before award.

Performance

Count of access-holding suppliers falling outside SCRM scope.

Evidence and Assessment

Evidence expected

SCRM program record with scope and recorded exclusions; pre-award assessments; reconciliation against the supplier terrain register.

Assessment procedure

Examine the program against the governing obligations; test that in-scope acquisitions were assessed before award; test the reconciliation against LC-1 for access-holding suppliers outside scope.

Related Guidance

Inherits
  • SR-3
  • SR-6
  • SA-9
Satisfies
  • GV.SC-01
  • GV.SC-04
  • GV.SC-06
  • GV.SC-09
  • ID.RA-09
  • ID.RA-10

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Fed By

Nothing upstream — this control starts a chain.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.14

Terrain It Is Named On

  • T9Supply ChainSupply chain terrain — the control that requires this ground to be identified as terrain rather than managed as vendor paperwork.

Artifacts It Stands On

  • producesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
  • consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.

Roles It Puts to Work