SR-1: Policy and Procedures

SR-01 requires your organization to develop, document, and distribute a formal supply chain risk management (SCRM) policy along with the...

Quick-reference card

FieldValue
Control IDSR-01
Control namePolicy and Procedures
FrameworkNIST SP 800-53, Revision 5
Control familySupply Chain Risk Management
BaselinesLOW MODERATE HIGH
Implementation levelOrganization
RelevanceOrganization-level (First Party and Third Party)
Risk severityLow

What this control requires

SR-01 requires your organization to develop, document, and distribute a formal supply chain risk management (SCRM) policy along with the procedures that put it into practice. That first sentence sounds routine, but without this foundational control, every other supply chain safeguard in the SR family lacks the governance backbone it depends on.

In practice, SR-01 demands three distinct outcomes. First, you need a policy that spells out purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance requirements. Second, you need procedures detailed enough to guide personnel through each step of executing that policy. Third, you must designate a specific official who owns the ongoing management of both the policy and its procedures.

The control also requires a defined review and update cycle. Your policy and procedures must be revisited on a set frequency and refreshed after triggering events such as audit findings, security incidents, or regulatory changes. Restating the controls from the SR family word-for-word doesn’t satisfy SR-01. The policy must translate those controls into directives that reflect your organization’s risk management strategy and operational context.

Why it matters

Most organizations treat SCRM policy as a checkbox deliverable, drafted once during an audit cycle and filed away until the next assessment. That approach turns a governance control into dead documentation, leaving the entire supply chain risk management program without enforceable direction.

Failure to maintain SR-01 introduces direct audit risk and may result in certification withdrawal or regulatory findings. Because SR-01 sits at the LOW baseline, assessors expect it to be in place even for systems with minimal impact classifications. A missing or outdated policy signals systemic governance gaps that auditors will flag across multiple control families, not just supply chain.

The operational consequence extends beyond audit exposure. Without a current, disseminated policy, personnel lack clarity on their SCRM responsibilities, approval workflows stall, and incident response for supply chain events defaults to improvisation. Coordination between security and privacy programs breaks down when there’s no documented framework to align them.

Specifically, when SR-01 is absent or neglected, the following gaps become exploitable:

  • Undefined ownership creates accountability gaps where no single official is responsible for maintaining SCRM policy, allowing updates to lapse indefinitely
  • Stale procedures that haven’t been refreshed after regulatory changes leave your organization operating under outdated guidance
  • Inconsistent dissemination means frontline personnel and procurement teams never receive the policy, making compliance impossible at the operational level
  • Missing coordination clauses between security and privacy programs result in duplicated efforts or, worse, blind spots where neither team covers a requirement
  • No triggering-event protocol means audit findings and incidents don’t flow back into policy updates, so the same weaknesses recur

How to implement

The most common failure mode with SR-01 isn’t writing the policy. It’s treating the policy as a standalone document disconnected from the organization’s broader risk management strategy. Your SCRM policy must flow directly from your enterprise risk posture, and your procedures must map back to the specific controls in the SR family and related supply-chain controls in other families.

For your organization

Start by identifying the official who will own the policy and procedures. This person should have enough authority to enforce updates and enough visibility across procurement, IT, and security to coordinate inputs. Document that designation formally, because assessors will ask for evidence of it.

Draft the policy with seven required elements: purpose, scope, roles and responsibilities, management commitment, coordination among entities, compliance alignment, and consistency with applicable laws, executive orders, and regulations. Don’t write these in isolation. Pull your risk management strategy (PM-09) and your SCRM strategy (PM-30) to ensure your SCRM policy aligns with both.

Build your procedures as a separate deliverable or a clearly delineated section within your system security plan (SSP). Procedures should describe how personnel execute each policy directive, including step-by-step workflows for vendor onboarding risk reviews, supply chain incident escalation, and periodic reassessments. Generic restatements of controls don’t qualify as procedures.

Establish a review cadence. At minimum, define an annual review cycle for the policy and a semi-annual cycle for procedures. Document the triggering events that force out-of-cycle updates: audit findings, supply chain incidents, changes in regulatory requirements, or shifts in organizational risk tolerance. Maintain a revision log that captures what changed, when, and why.

Common mistakes to avoid:

  • Writing policy that restates NIST controls verbatim without translating them into organizational directives
  • Failing to disseminate the policy to all relevant personnel, including procurement and legal teams
  • Treating the policy and procedures as a single document when they serve different operational functions
  • Skipping the designated official requirement, leaving ownership ambiguous

For your vendors

When assessing vendor compliance with SR-01, your goal is to confirm that the vendor has a living SCRM policy, not a templated document produced for a one-time audit. Request the following evidence and evaluate it critically.

Questionnaire questions to include:

  • Does your organization maintain a documented SCRM policy? When was it last reviewed and updated?
  • Who is the designated official responsible for managing your SCRM policy and procedures?
  • How are SCRM policies and procedures disseminated to relevant personnel?
  • What events trigger out-of-cycle reviews of your SCRM policy?
  • Are your SCRM procedures documented separately from the policy, and do they include step-by-step implementation guidance?

Evidence to request:

  • Current SCRM policy document with revision history
  • SCRM procedures document or relevant SSP sections
  • Designation letter or organizational chart showing the responsible official
  • Distribution records showing policy dissemination to defined personnel
  • Review schedule and records of the most recent review cycle

Red flags during verification:

  • The policy document has no revision history or hasn’t been updated in more than 18 months
  • The vendor can’t name a specific individual responsible for SCRM policy management
  • Procedures are identical to the policy or consist entirely of restated control language
  • No evidence of dissemination beyond the security team, indicating procurement, legal, and operational staff haven’t received the policy
  • Triggering events for updates are undefined or limited to “annual review” with no event-driven mechanism

Use your vendor risk management program to track whether vendors maintain current SCRM documentation and flag those whose policies have lapsed beyond their stated review cadence.

Evidence examples

Evidence typeExample artifact
SCRM policySupply chain risk management policy defining purpose, scope, roles, responsibilities, management commitment, coordination requirements, and compliance alignment with applicable laws and regulations
SCRM proceduresDocumented procedures for vendor onboarding risk assessment, supply chain incident escalation, and periodic reassessment workflows
Designated official documentationOrganizational chart or designation letter identifying the official responsible for managing SCRM policy and procedures
System security planSSP sections addressing supply chain risk management controls and how SCRM policy directives are implemented at the system level
Privacy planPrivacy plan sections documenting coordination between security and privacy programs on supply chain requirements
Dissemination recordsDistribution logs, email records, or training acknowledgments confirming policy dissemination to defined personnel
Review and update recordsRevision history logs showing review dates, triggering events, changes made, and approval signatures

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.1 Policies for information securityPartial
ISO 27001:20225.19 Information security in supplier relationshipsPartial
ISO 27001:20225.2 Information security roles and responsibilitiesPartial
ISO 27001:20225.3 Segregation of dutiesPartial
ISO 27001:20225.31 Legal, statutory, regulatory and contractual requirementsPartial
ISO 27001:20225.36 Compliance with policies, rules and standards for information securityPartial
ISO 27001:20225.37 Documented operating proceduresPartial
ISO 27001:20225.4 Management responsibilitiesPartial
NIST SP 800-171 Rev 303.15.01 Policy and ProceduresPartial
  • PM-09 — Risk Management Strategy: defines the enterprise risk management strategy that SR-01 policy must align with and draw its priorities from
  • PM-30 — Supply Chain Risk Management Strategy: provides the overarching SCRM strategy that SR-01 policy translates into specific organizational directives and procedures
  • PS-08 — Personnel Sanctions: establishes the consequences for personnel who fail to comply with the SCRM policies and procedures defined under SR-01
  • SI-12 — Information Management and Retention: governs how SCRM policy documents, procedures, and associated records are retained and disposed of in accordance with organizational requirements

Frequently asked questions

What is NIST SP 800-53 SR-01?

SR-01 is the NIST SP 800-53 control that requires organizations to create, document, and distribute a supply chain risk management policy and its supporting procedures. It also mandates designating a specific official to manage those documents and reviewing them on a defined schedule and after triggering events like audit findings or regulatory changes. The control applies at the LOW, MODERATE, and HIGH baselines, making it a foundational requirement for any system categorization level.

What happens if SR-01 is not implemented?

Without SR-01, your organization lacks a formal governance structure for supply chain risk management, which assessors will flag as a systemic deficiency during authorization or audit activities. The absence of a designated official for SCRM policy management means no one is accountable for keeping the policy current with evolving threats and regulations. Dissemination gaps leave procurement teams and operational staff without documented guidance, increasing the likelihood of inconsistent supply chain decisions. The downstream effect is that related controls in the SR family have no policy foundation to reference, weakening your entire supply chain security posture.

How do you audit SR-01?

Auditing SR-01 starts with verifying that a current SCRM policy exists, addresses all required elements (purpose, scope, roles, responsibilities, management commitment, coordination, and compliance), and is consistent with applicable laws and executive orders. Assessors then confirm that procedures are documented separately and include actionable implementation guidance rather than restated control language. Evidence of dissemination to defined personnel, a named designated official, and a revision history showing reviews at the stated frequency and after triggering events are all required artifacts. Request distribution logs and review records to validate that the policy isn’t a static document created solely for certification.

How does SR-01 relate to NIST SP 800-161?

NIST SP 800-161 provides the detailed framework for cyber supply chain risk management that SR-01 policies should operationalize. Where SR-01 establishes the governance requirement to have an SCRM policy with designated ownership and review cycles, SP 800-161 offers the methodologies, risk assessment approaches, and supply chain-specific controls that inform what that policy should contain. Organizations typically use SP 800-161 as the authoritative reference when drafting the substantive content of their SR-01 policy and procedures.

Experience superior visibility and a simpler approach to cyber risk management