FedRAMP Moderate: the evidence behind every control
323 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
AC - Access Control
AC-1Policy and Procedures hardAC-2Account Management moderateAC-2(1)Automated System Account Management easyAC-2(2)Automated Temporary and Emergency Account Management moderateAC-2(3)Disable Accounts moderateAC-2(4)Automated Audit Actions easyAC-2(5)Inactivity Logout easyAC-2(7)Privileged User Accounts moderateAC-2(9)Restrictions on Use of Shared and Group Accounts hardAC-2(12)Account Monitoring for Atypical Usage easyAC-2(13)Disable Accounts for High-Risk Individuals hardAC-3Access Enforcement hardAC-4Information Flow Enforcement moderateAC-4(21)Physical or Logical Separation of Information Flows hardAC-5Separation of Duties moderateAC-6Least Privilege hardAC-6(1)Authorize Access to Security Functions hardAC-6(2)Non-Privileged Access for Nonsecurity Functions hardAC-6(5)Privileged Accounts hardAC-6(7)Review of User Privileges easyAC-6(9)Log Use of Privileged Functions easyAC-6(10)Prohibit Non-Privileged Users from Executing Privileged Functions easyAC-7Unsuccessful Logon Attempts hardAC-8System Use Notification hardAC-11Device Lock moderateAC-11(1)Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image moderateAC-12Session Termination hardAC-14Permitted Actions Without Identification or Authentication moderateAC-17Remote Access moderateAC-17(1)Monitoring and Control easyAC-17(2)Protection of Confidentiality and Integrity Using Encryption easyAC-17(3)Managed Access Control Points hardAC-17(4)Privileged Commands and Access easyAC-18Wireless Access hardAC-18(1)Authentication and Encryption easyAC-18(3)Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment hardAC-19Access Control for Mobile Devices moderateAC-19(5)Full Device or Container-Based Encryption hardAC-20Use of External Systems moderateAC-20(1)Limits on Authorized Use hardAC-20(2)Portable Storage Devices Restricted Use hardAC-21Information Sharing hardAC-22Publicly Accessible Content moderateAT - Awareness and Training
AT-1Policy and Procedures hardAT-2Literacy Training and Awareness hardAT-2(2)Insider Threat hardAT-2(3)Social Engineering and Mining easyAT-3Role-Based Training hardAT-4Training Records hardAU - Audit and Accountability
AU-1Policy and Procedures easyAU-2Event Logging easyAU-3Content of Audit Records moderateAU-3(1)Additional Audit Information easyAU-4Audit Log Storage Capacity easyAU-5Response to Audit Logging Process Failures easyAU-6Audit Record Review, Analysis, and Reporting easyAU-6(1)Automated Process Integration hardAU-6(3)Correlate Audit Record Repositories hardAU-7Audit Record Reduction and Report Generation easyAU-7(1)Automatic Processing hardAU-8Time Stamps easyAU-9Protection of Audit Information moderateAU-9(4)Access by Subset of Privileged Users hardAU-11Audit Record Retention easyAU-12Audit Record Generation moderateCA - Assessment, Authorization, and Monitoring
CA-1Policy and Procedures hardCA-2Control Assessments hardCA-2(1)Independent Assessors hardCA-2(3)Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements] hardCA-3Information Exchange hardCA-5Plan of Action and Milestones hardCA-6Authorization hardCA-7Continuous Monitoring hardCA-7(1)Independent Assessment hardCA-7(4)Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring hardCA-8Penetration Testing hardCA-8(1)Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components hardCA-8(2)Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises] hardCA-9Internal System Connections hardCM - Configuration Management
CM-1Policy and Procedures hardCM-2Baseline Configuration hardCM-2(2)Automation Support for Accuracy and Currency hardCM-2(3)Retention of Previous Configurations hardCM-2(7)Configure Systems and Components for High-Risk Areas hardCM-3Configuration Change Control hardCM-3(2)Testing, Validation, and Documentation of Changes hardCM-3(4)Security and Privacy Representatives hardCM-4Impact Analyses moderateCM-4(2)Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements moderateCM-5Access Restrictions for Change moderateCM-5(1)Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions easyCM-5(5)Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment: moderateCM-6Configuration Settings moderateCM-6(1)Automated Management, Application, and Verification hardCM-7Least Functionality hardCM-7(1)Periodic Review hardCM-7(2)Prevent Program Execution hardCM-7(5)Authorized Software Allow-by-Exception hardCM-8System Component Inventory hardCM-8(1)Updates During Installation and Removal hardCM-8(3)Automated Unauthorized Component Detection easyCM-9Configuration Management Plan hardCM-10Software Usage Restrictions hardCM-11User-Installed Software hardCM-12Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access hardCM-12(1)Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational hardCP - Contingency Planning
CP-1Policy and Procedures hardCP-2Contingency Plan hardCP-2(1)Coordinate with Related Plans hardCP-2(3)Resume Mission and Business Functions hardCP-2(8)Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions hardCP-3Contingency Training hardCP-4Contingency Plan Testing hardCP-4(1)Coordinate with Related Plans hardCP-6Alternate Storage Site hardCP-6(1)Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats hardCP-6(3)Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions hardCP-7Alternate Processing Site hardCP-7(1)Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats hardCP-7(2)Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions hardCP-7(3)Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives) hardCP-8Telecommunications Services hardCP-8(1)Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority hardCP-8(2)Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services hardCP-9System Backup hardCP-9(1)Testing for Reliability and Integrity hardCP-9(8)System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information] easyCP-10System Recovery and Reconstitution hardCP-10(2)System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based easyIA - Identification and Authentication
IA-1Policy and Procedures hardIA-2Identification and Authentication (Organizational Users) easyIA-2(1)MFA to Privileged Accounts easyIA-2(2)MFA to Non-Privileged Accounts easyIA-2(5)Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources hardIA-2(6)Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that: hardIA-2(8)Access to Accounts Replay Resistant hardIA-2(12)Acceptance of PIV Credentials easyIA-3Device Identification and Authentication easyIA-4Identifier Management easyIA-4(4)Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status] hardIA-5Authenticator Management moderateIA-5(1)Password-Based Authentication hardIA-5(2)Public Key-Based Authentication easyIA-5(6)Protection of Authenticators hardIA-5(7)Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage hardIA-6Authentication Feedback moderateIA-7Cryptographic Module Authentication hardIA-8Identification and Authentication (Non-Organizational Users) easyIA-8(1)Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies hardIA-8(2)Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators hardIA-8(4)Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined identity management profiles] hardIA-11Re-Authentication easyIA-12Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a easyIA-12(2)Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority hardIA-12(3)Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification] hardIA-12(5)Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record hardIR - Incident Response
IR-1Policy and Procedures hardIR-2Incident Response Training hardIR-3Incident Response Testing hardIR-3(2)Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans hardIR-4Incident Handling hardIR-4(1)Automated Incident Handling Processes hardIR-5Incident Monitoring hardIR-6Incident Reporting hardIR-6(1)Automated Reporting easyIR-6(3)Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components easyIR-7Incident Response Assistance hardIR-7(1)Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms] hardIR-8Incident Response Plan hardIR-9Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting hardIR-9(2)Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency] hardIR-9(3)Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment: hardIR-9(4)Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls] hardMA - Maintenance
MA-1Policy and Procedures moderateMA-2Controlled Maintenance moderateMA-3Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency] hardMA-3(1)Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications hardMA-3(2)Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system easyMA-3(3)Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organizational information contained on the equipment; (b) Sanitizing or destroying the equipment; hardMA-4Nonlocal Maintenance easyMA-5Maintenance Personnel easyMA-5(1)Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1) hardMA-6Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure hardMP - Media Protection
MP-1Policy and Procedures hardMP-2Media Access hardMP-3Media Marking moderateMP-4Media Storage moderateMP-5Media Transport moderateMP-6Media Sanitization moderateMP-7Media Use hardPE - Physical and Environmental Protection
PE-1Policy and Procedures easyPE-2Physical Access Authorizations moderatePE-3Physical Access Control moderatePE-4Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls] moderatePE-5Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output easyPE-6Monitoring Physical Access moderatePE-6(1)Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment hardPE-8Visitor Access Records moderatePE-9Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction moderatePE-10Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system easyPE-11Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power moderatePE-12Emergency Lighting moderatePE-13Fire Protection moderatePE-13(1)Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a hardPE-13(2)Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an hardPE-14Environmental Controls easyPE-15Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel moderatePE-16Delivery and Removal easyPE-17Alternate Work Site moderatePL - Planning
PL-1Policy and Procedures hardPL-2System Security and Privacy Plans hardPL-4Rules of Behavior hardPL-4(1)Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sites, and external sites/applications; (b) Posting organizational information hardPL-8Security and Privacy Architectures hardPL-10Baseline Selection. Select a control baseline for the system hardPL-11Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions hardPS - Personnel Security
PS-1Policy and Procedures hardPS-2Position Risk Designation hardPS-3Personnel Screening hardPS-3(3)Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: (a) Have valid access authorizations that are demonstrated by assigned official government hardPS-4Personnel Termination hardPS-5Personnel Transfer hardPS-6Access Agreements hardPS-7External Personnel Security hardPS-8Personnel Sanctions hardPS-9Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions hardRA - Risk Assessment
RA-1Policy and Procedures hardRA-2Security Categorization hardRA-3Risk Assessment hardRA-3(1)Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when hardRA-5Vulnerability Monitoring and Scanning hardRA-5(2)Update Vulnerabilities to be Scanned hardRA-5(3)Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage easyRA-5(5)Privileged Access easyRA-5(11)Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components hardRA-7Risk Response moderateRA-9Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle] hardSA - System and Services Acquisition
SA-1Policy and Procedures hardSA-2Allocation of Resources hardSA-3System Development Life Cycle hardSA-4Acquisition Process hardSA-4(1)Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented hardSA-4(2)Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or hardSA-4(9)Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use hardSA-4(10)Use of Approved PIV Products hardSA-5System Documentation hardSA-8Security and Privacy Engineering Principles hardSA-9External System Services hardSA-9(1)External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing hardSA-9(2)Identification of Functions, Ports, Protocols, and Services hardSA-9(5)External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or hardSA-10Developer Configuration Management hardSA-11Developer Testing and Evaluation hardSA-11(1)Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of hardSA-11(2)Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing hardSA-15Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the hardSA-15(3)Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development hardSA-22Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support hardSC - System and Communications Protection
SC-1Policy and Procedures hardSC-2Separation of System and User Functionality hardSC-4Information in Shared System Resources hardSC-5Denial-of-Service Protection hardSC-7Boundary Protection hardSC-7(3)Access Points hardSC-7(4)External Telecommunications Services hardSC-7(5)Deny by Default Allow by Exception hardSC-7(7)Split Tunneling for Remote Devices hardSC-7(8)Route Traffic to Authenticated Proxy Servers easySC-7(12)Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components] easySC-7(18)Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device easySC-8Transmission Confidentiality and Integrity hardSC-8(1)Cryptographic Protection easySC-10Network Disconnect hardSC-12Cryptographic Key Establishment and Management hardSC-13Cryptographic Protection hardSC-15Collaborative Computing Devices and Applications hardSC-17Public Key Infrastructure Certificates hardSC-18Mobile Code hardSC-20Secure Name/Address Resolution Service (Authoritative) hardSC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver) hardSC-22Architecture and Provisioning for Name/Address Resolution Service hardSC-23Session Authenticity hardSC-28Protection of Information at Rest hardSC-28(1)Cryptographic Protection hardSC-39Process Isolation hardSC-45System Time Synchronization. Synchronize system clocks within and between systems and system components hardSC-45(1)System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and (b) Synchronize the internal system clocks to the authoritative hardSI - System and Information Integrity
SI-1Policy and Procedures hardSI-2Flaw Remediation hardSI-2(2)Automated Flaw Remediation Status easySI-2(3)Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined easySI-3Malicious Code Protection hardSI-4System Monitoring hardSI-4(1)System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system hardSI-4(2)Automated Tools and Mechanisms for Real-Time Analysis hardSI-4(4)Inbound and Outbound Communications Traffic easySI-4(5)System-Generated Alerts easySI-4(16)System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system hardSI-4(18)System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points hardSI-4(23)System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms] hardSI-5Security Alerts, Advisories, and Directives hardSI-6Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system easySI-7Software, Firmware, and Information Integrity hardSI-7(1)Integrity Checks hardSI-7(7)Integration of Detection and Response hardSI-8Spam Protection easySI-8(2)Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency] easySI-10Information Input Validation hardSI-11Error Handling hardSI-12Information Management and Retention hardSI-16Memory Protection hardSR - Supply Chain Risk Management
SR-1Policy and Procedures (SR-1) hardSR-2Supply Chain Risk Management Plan (SR-2) hardSR-2(1)Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined hardSR-3Supply Chain Controls and Processes (SR-3) hardSR-5Acquisition Strategies, Tools, and Methods (SR-5) hardSR-6Supplier Assessments and Reviews (SR-6) hardSR-8Notification Agreements (SR-8) hardSR-10Inspection of Systems or Components (SR-10) hardSR-11Component Authenticity (SR-11) hardSR-11(1)Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware) hardSR-11(2)Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system moderateSR-12Component Disposal (SR-12) hard