# Supply Chain Risk Template ## Description Client-fillable template for the supply chain risk identification, upstream vulnerability monitoring, and provider-guidance comparison the provider of the offering owns, with sample text, the KSI-SCR and KSI-CNA-IBP statements it answers, and how the platform evidences it. ## Resolution # Supply Chain Risk Template **TEMPLATE - this document describes practices the provider of the offering owns, outside the GRCITSM platform. Replace the sample text with your organization's actual practice before publishing. The GRCITSM platform evidences these practices through scheduled validation checks; it does not execute them.** ## Purpose This template is the starting point for how your organization identifies, reviews, and mitigates supply chain risk in the cloud service offering, monitors third-party software for upstream vulnerabilities, and keeps third-party resources configured the way their own providers recommend. These are your procurement, engineering, and vendor management practices. Fill in the sample sections with what your organization actually does, then keep the third-party resource records in the platform current so the evidence matches the practice. ## Requirements this document answers Three Key Security Indicators. No FedRAMP Rule (FRR) in the 2026 Consolidated Rules names a supply chain document; the obligation is the KSI outcome. Third-party resource documentation under MAS-CSO-TPR is a separate, platform-executed practice and lives in the Asset, Inventory, and Assessment Scope Policy and Procedures. | KSI | Name | Statement | |---|---|---| | KSI-SCR-MIT | Mitigating Supply Chain Risk | Persistently identify, review, and mitigate potential supply chain risks. | | KSI-SCR-MON | Monitoring Supply Chain Risk | Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services. | | KSI-CNA-IBP | Implementing Best Practices | The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance. | ## Sample practice: identifying and mitigating supply chain risk **Sample text.** [Organization] treats every third-party information resource in the offering as a supply chain risk to be assessed before adoption and reviewed on a standing cadence. Before a resource is introduced, [role] performs a review covering: what the resource does in the offering and what data reaches it, the provider's own security posture and authorization status, the concentration and single-point-of-failure risk it introduces, the exit path if the provider fails or is compromised, and the contractual security commitments obtained. Findings are recorded against the resource with a risk rating and the mitigations applied. Adoption requires approval from [approval role]. **Sample text.** Adopted resources are re-reviewed [cadence], and out of cycle on any of these triggers: a security incident at the provider, a change in the provider's authorization or certification status, a change in what the resource does in the offering, a change of ownership at the provider, or a change to the data that reaches it. Each review restates the risk rating and the current mitigations. Mitigations that no longer hold are raised as findings with owners and due dates. *Replace with your practice.* Name the reviewing role, the approval role, the review triggers, and the risk rating scheme. "Persistently" in KSI-SCR-MIT means the review has a cadence, so put a real interval in the values table. ## Sample practice: monitoring for upstream vulnerabilities **Sample text.** Third-party software in the offering is monitored automatically for upstream vulnerabilities through [mechanisms: software composition analysis on the build pipeline, registry and dependency advisory feeds, vendor security bulletin subscriptions, contractual notification clauses]. A software bill of materials is produced at build time for [scope] and reconciled against the advisory feeds [cadence]. Upstream advisories that affect a resource in the offering enter the vulnerability pipeline as detections and follow the evaluation and response timelines in the Vulnerability Detection, Evaluation, and Response Policy and Procedures; supply chain origin does not create a separate clock. **Sample text.** Where a third-party provider gives no machine-readable advisory feed, notification is obtained contractually: [contract term summary], with the notification window and the recipient named in the agreement. Providers with neither an automated feed nor a contractual notification commitment are recorded as a monitoring gap with a compensating measure. *Replace with your practice.* Name the tooling, the SBOM scope, and the contractual mechanism. KSI-SCR-MON accepts contractual notification or active monitoring, so be explicit about which one covers each provider. ## Sample practice: configuring against provider guidance **Sample text.** Every third-party machine-based information resource in the offering carries a reference to the original provider's security best practice or hardening guidance, and its running configuration is compared against that guidance [cadence]. The comparison is automated where the provider publishes a machine-readable benchmark or the resource exposes its settings through an API, and performed as a documented review where it is not. Deviations from provider guidance are either corrected through the change process or recorded as accepted with a stated reason and an owner. The reference and the last comparison date live on the resource's record. *Replace with your practice.* Name where the provider guidance reference is held, how the comparison runs per resource class, and who accepts a deviation. ## Organization-defined values | Value | Setting | Notes | |---|---|---| | Pre-adoption review owner | [role] | KSI-SCR-MIT | | Adoption approval authority | [role] | KSI-SCR-MIT | | Risk rating scheme | [scheme] | KSI-SCR-MIT | | Standing re-review cadence | [cadence] | KSI-SCR-MIT, "persistently" | | Out-of-cycle review triggers | [triggers] | KSI-SCR-MIT | | Upstream monitoring mechanisms | [tooling and feeds] | KSI-SCR-MON | | SBOM scope and generation point | [scope; build stage] | KSI-SCR-MON | | SBOM to advisory reconciliation cadence | [cadence] | KSI-SCR-MON | | Contractual notification window | [duration] | KSI-SCR-MON | | Providers with no feed or contractual notice | [list or "none"] | KSI-SCR-MON, monitoring gaps | | Provider guidance reference location | [location] | KSI-CNA-IBP | | Configuration comparison cadence | [cadence per resource class] | KSI-CNA-IBP | | Deviation acceptance authority | [role] | KSI-CNA-IBP | | Document owner | [role] | Fills the authority section | ## Evidence The GRCITSM platform does not perform your vendor reviews, run your composition analysis, or compare your configurations against provider guidance. It evidences that the three indicators are being met, and it holds the third-party resource records the practice operates on. See the Continuous Monitoring and Reporting Policy and Procedures for the validation tree and the check cadences. | Practice | What the platform records | |---|---| | Third-party resource register | Each resource as a Component of type Service, carrying its provider, its usage and configuration, the justification for use, mitigations, and compensating controls | | Supply chain risk review (KSI-SCR-MIT) | Validation runs on each review cycle; unmitigated risks open Issues tracked to closure | | Upstream vulnerability monitoring (KSI-SCR-MON) | Validation runs on feed coverage against the third-party resource register; upstream detections enter the vulnerability pipeline as Issues on their normal clocks | | Provider guidance comparison (KSI-CNA-IBP) | Validation runs per comparison, carrying pass and fail counts and the accepted deviations | Third-party resource records are shared with the Asset, Inventory, and Assessment Scope Policy and Procedures, which owns their MAS-CSO-TPR documentation set. This template governs the risk practice; that document governs the record. ## Authority, review, and revision *Client fills.* Name the executive who issues this document, the role that owns supply chain risk, the review cadence, and the approval path for accepting a supply chain risk or a configuration deviation. Record the issue date and the revision history below. | Version | Date | Author | Change | |---|---|---|---| | [0.1] | [date] | [author] | Initial draft from template | ## Internal Memo Source: supply-chain-risk-template.md in the GRCITSM knowledge-base library (species: client-template; editor_type 1 = markdown). Downloaded from the public GRC-ITSM documentation site; body carried verbatim from the library source. Paste the Resolution section as the article body (description_markdown) in your GRCITSM instance and apply the Tags list. ## Tags - GRCITSM Template - Supply Chain Risk - FedRAMP Rev5 Class C - FedRAMP 20x Class C - KSI-CNA-IBP - KSI-SCR-MIT - KSI-SCR-MON