STA-06: Are the portions of the SSRM the organization is responsible for implemented,
operated, audited, or assessed?
Both the CSP and CSC should implement the finalized SSRM and then thoroughly document and test it to validate proper operation of security control implementations—including integration testing where there are interdependencies. Once implemented, both the CSP and CSC should operate, monitor and audit, and/or assess their service performance according to the finalized SSRM and remain engaged with their supply chain and customers to understand, implement and manage SSRM changes over time.
Particular areas that require proactive supply chain SSRM engagement with corresponding levels of (secure) transparency include: a. Incident and vulnerability management b. Change and configuration management c. Periodic SSRM-aligned audit reviews and security assessments with appropriate risk management
Control implemented
Control ownership
Description
Implement, operate, and audit or assess the portions of the SSRM
which the organization is responsible for.