SR-2 Supply Chain Risk Management Plan
Statement
WTAMU is dependent on products, systems, and services from external providers, and the nature of these relationships present an increasing level of risk to an organization. Threat actions that may increase security or privacy risks include unauthorized production, the insertion or use of counterfeits, tampering, theft, insertion of malicious software and hardware, and poor manufacturing and development practices in the supply chain. Supply chain risks can be endemic or systemic within a system element or component, a system, an organization, a sector, or the Nation. Managing supply chain risk is a complex, multifaceted undertaking that requires a coordinated effort across an organization to build trust relationships and communicate with internal and external stakeholders.
Applicability
This Control applies to all West Texas A&M network information resources. The intended audience for this Control includes all information resource owners, or designee responsible for implementation.
Implementation
WTAMU shall develop and implement a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations, and disposal of systems, system components or system services across the organization. The plan shall be reviewed and updated annually or as required, to address threat, organizational or environmental changes.