Skip to content

Supply Chain Risk

This template is the starting point for how your organization identifies, reviews, and mitigates supply chain risk in the cloud service offering, monitors third-party software for upstream vulnerabilities, and keeps third-party resources configured the way their own providers recommend. These are your procurement, engineering, and vendor management practices. Fill in the sample sections with what your organization actually does, then keep the third-party resource records in the platform current so the evidence matches the practice.

Quick Summary

A client-fillable template covering the supply chain risk identification, upstream vulnerability monitoring, and provider-guidance comparison the provider of the offering owns. It carries sample text you replace with your real practice, the KSI-SCR and KSI-CNA-IBP statements it answers, and a table of how the platform evidences each practice. The platform holds the third-party resource records the practice operates on; this template governs the practice itself.

Customer-owned template

This is a starting-point template delivered with GRC-ITSM. The practices it describes are owned and executed by your organization, not by the platform. Fill the Organization-Defined Values, remove framework rows you are not pursuing, and adopt it as your own document before relying on it.

Related documentation

Download the KB article (Markdown)


Requirements this document answers

Three Key Security Indicators. No FedRAMP Rule (FRR) in the 2026 Consolidated Rules names a supply chain document; the obligation is the KSI outcome. Third-party resource documentation under MAS-CSO-TPR is a separate, platform-executed practice and lives in the Asset, Inventory, and Assessment Scope Policy and Procedures.

KSI Name Statement
KSI-SCR-MIT Mitigating Supply Chain Risk Persistently identify, review, and mitigate potential supply chain risks.
KSI-SCR-MON Monitoring Supply Chain Risk Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.
KSI-CNA-IBP Implementing Best Practices The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.

Sample practice: identifying and mitigating supply chain risk

Sample text. [Organization] treats every third-party information resource in the offering as a supply chain risk to be assessed before adoption and reviewed on a standing cadence. Before a resource is introduced, [role] performs a review covering: what the resource does in the offering and what data reaches it, the provider's own security posture and authorization status, the concentration and single-point-of-failure risk it introduces, the exit path if the provider fails or is compromised, and the contractual security commitments obtained. Findings are recorded against the resource with a risk rating and the mitigations applied. Adoption requires approval from [approval role].

Sample text. Adopted resources are re-reviewed [cadence], and out of cycle on any of these triggers: a security incident at the provider, a change in the provider's authorization or certification status, a change in what the resource does in the offering, a change of ownership at the provider, or a change to the data that reaches it. Each review restates the risk rating and the current mitigations. Mitigations that no longer hold are raised as findings with owners and due dates.

Replace with your practice. Name the reviewing role, the approval role, the review triggers, and the risk rating scheme. "Persistently" in KSI-SCR-MIT means the review has a cadence, so put a real interval in the values table.


Sample practice: monitoring for upstream vulnerabilities

Sample text. Third-party software in the offering is monitored automatically for upstream vulnerabilities through [mechanisms: software composition analysis on the build pipeline, registry and dependency advisory feeds, vendor security bulletin subscriptions, contractual notification clauses]. A software bill of materials is produced at build time for [scope] and reconciled against the advisory feeds [cadence]. Upstream advisories that affect a resource in the offering enter the vulnerability pipeline as detections and follow the evaluation and response timelines in the Vulnerability Detection, Evaluation, and Response Policy and Procedures; supply chain origin does not create a separate clock.

Sample text. Where a third-party provider gives no machine-readable advisory feed, notification is obtained contractually: [contract term summary], with the notification window and the recipient named in the agreement. Providers with neither an automated feed nor a contractual notification commitment are recorded as a monitoring gap with a compensating measure.

Replace with your practice. Name the tooling, the SBOM scope, and the contractual mechanism. KSI-SCR-MON accepts contractual notification or active monitoring, so be explicit about which one covers each provider.


Sample practice: configuring against provider guidance

Sample text. Every third-party machine-based information resource in the offering carries a reference to the original provider's security best practice or hardening guidance, and its running configuration is compared against that guidance [cadence]. The comparison is automated where the provider publishes a machine-readable benchmark or the resource exposes its settings through an API, and performed as a documented review where it is not. Deviations from provider guidance are either corrected through the change process or recorded as accepted with a stated reason and an owner. The reference and the last comparison date live on the resource's record.

Replace with your practice. Name where the provider guidance reference is held, how the comparison runs per resource class, and who accepts a deviation.


Organization-defined values

Value Setting Notes
Pre-adoption review owner [role] KSI-SCR-MIT
Adoption approval authority [role] KSI-SCR-MIT
Risk rating scheme [scheme] KSI-SCR-MIT
Standing re-review cadence [cadence] KSI-SCR-MIT, "persistently"
Out-of-cycle review triggers [triggers] KSI-SCR-MIT
Upstream monitoring mechanisms [tooling and feeds] KSI-SCR-MON
SBOM scope and generation point [scope; build stage] KSI-SCR-MON
SBOM to advisory reconciliation cadence [cadence] KSI-SCR-MON
Contractual notification window [duration] KSI-SCR-MON
Providers with no feed or contractual notice [list or "none"] KSI-SCR-MON, monitoring gaps
Provider guidance reference location [location] KSI-CNA-IBP
Configuration comparison cadence [cadence per resource class] KSI-CNA-IBP
Deviation acceptance authority [role] KSI-CNA-IBP
Document owner [role] Fills the authority section

Evidence

The GRC-ITSM platform does not perform your vendor reviews, run your composition analysis, or compare your configurations against provider guidance. It evidences that the three indicators are being met, and it holds the third-party resource records the practice operates on. See the Continuous Monitoring and Reporting Policy and Procedures for the validation tree and the check cadences.

Practice What the platform records
Third-party resource register Each resource as a Component of type Service, carrying its provider, its usage and configuration, the justification for use, mitigations, and compensating controls
Supply chain risk review (KSI-SCR-MIT) Validation runs on each review cycle; unmitigated risks open Issues tracked to closure
Upstream vulnerability monitoring (KSI-SCR-MON) Validation runs on feed coverage against the third-party resource register; upstream detections enter the vulnerability pipeline as Issues on their normal clocks
Provider guidance comparison (KSI-CNA-IBP) Validation runs per comparison, carrying pass and fail counts and the accepted deviations

Third-party resource records are shared with the Asset, Inventory, and Assessment Scope Policy and Procedures, which owns their MAS-CSO-TPR documentation set. This template governs the risk practice; that document governs the record.


Authority, review, and revision

Client fills. Name the executive who issues this document, the role that owns supply chain risk, the review cadence, and the approval path for accepting a supply chain risk or a configuration deviation. Record the issue date and the revision history below.

Version Date Author Change
[0.1] [date] [author] Initial draft from template