← Back to catalog
SR-3(3)
Sub-tier Flow Down
Supply Chain Risk Management (SR)
Baselines
Low · Not includedModerate · Not includedHigh · Not included
Description
Ensure that the controls included in the contracts of prime contractors are also included in the contracts of subcontractors.
Discussion
To manage supply chain risk effectively and holistically, it is important that organizations ensure that supply chain risk management controls are included at all tiers in the supply chain. This includes ensuring that Tier 1 (prime) contractors have implemented processes to facilitate the "flow down" of supply chain risk management controls to sub-tier contractors. The controls subject to flow down are identified in [SR-3b](#sr-3_smt.b).
Implementation guidance
No content available.
CSF 2.0 crosswalk
No CSF mappings exist for this control.