SR-5: Acquisition Strategies, Tools, and Methods

SR-05 requires organizations to embed supply chain risk protections directly into their procurement and vendor management processes.

Quick-reference card

FieldDetail
Control IDSR-05
Control NameAcquisition Strategies, Tools, and Methods
FrameworkNIST SP 800-53 Revision 5
Control FamilySupply Chain Risk Management
BaselinesLOW | MODERATE | HIGH
RelevanceOrganization (Third Party)
Risk SeverityHigh

What this control requires

SR-05 requires organizations to embed supply chain risk protections directly into their procurement and vendor management processes. That means going beyond standard due diligence and incorporating specific strategies, tools, and methods designed to identify, assess, and mitigate risks before a product or service enters the environment.

In practice, this control demands that acquisition workflows include protections against counterfeiting, tampering, unauthorized production, and the insertion of malicious code. Organizations must integrate these protections throughout the system development life cycle, from initial solicitation through contract execution and ongoing vendor oversight, as part of the broader NIST SP 800-53 supply chain risk management family. The goal isn’t a one-time vendor check but a continuous posture where supply chain risk management is woven into every procurement decision.

SR-05 also calls for training and awareness programs so that procurement staff, security teams, and leadership understand supply chain threats and know when to activate mitigation strategies. Contract language should address tamper-evident packaging, controlled distribution channels, documentation protection, and the prohibition of tainted or counterfeit components.

Why it matters

Most organizations treat procurement as an administrative function, not a security boundary. That blind spot is exactly what advanced threat actors exploit. Supply chain attacks bypass perimeter defenses entirely by weaponizing the trust relationships organizations extend to their approved vendors and software providers.

SolarWinds Orion supply chain compromise (2019-2020)

Beginning no later than October 2019, attackers later attributed to Russia’s Foreign Intelligence Service (SVR / APT29 / Cozy Bear) compromised SolarWinds’ software build environment and injected a backdoor into legitimate update packages for SolarWinds’ Orion IT monitoring platform. FireEye named the implant SUNBURST during their analysis. Orion is used by approximately 33,000 organizations, including major US federal agencies and Fortune 500 companies. When customers downloaded and installed what appeared to be a routine software update (versions 2019.4 through 2020.2.1), they installed the SUNBURST implant along with it. Approximately 18,000 organizations downloaded the malicious build.

The attackers then selectively activated the backdoor against approximately 100 high-value targets, including the US Treasury, Commerce Department, DHS, parts of the Pentagon, and FireEye itself. The breach was discovered in December 2020 when FireEye noticed an attacker registering a new device for their multi-factor authentication (MFA), and in investigating, found SUNBURST. The attack ran approximately 14 months before discovery.

SolarWinds illustrates the SR-05 failure directly. No customer security assessment would likely have detected that SolarWinds’ internal build pipeline had been compromised. The attack was significant not because it breached individual vulnerabilities but because it weaponized the implicit trust organizations extend to software updates from vendors they’ve already assessed and approved. SR-05 exists to place that trust relationship on a verified rather than assumed footing.

The following vectors represent common ways attackers exploit supply chain weaknesses:

  • Compromised build pipelines where attackers inject malicious code into legitimate software before it reaches the customer
  • Counterfeit hardware components inserted into the supply chain that contain embedded backdoors or reduced security capabilities
  • Insider threats at vendor organizations where employees with privileged access introduce vulnerabilities or exfiltrate sensitive design data
  • Dependency hijacking where attackers compromise upstream open-source libraries or third-party modules that the vendor’s product relies on
  • Poor development practices at suppliers that leave code repositories, CI/CD pipelines, or signing keys exposed to unauthorized access

How to implement

For your vendors

The core challenge with SR-05 implementation in a third-party context is that you can’t directly inspect a vendor’s build pipeline or procurement controls. You need to verify through evidence, questioning, and contractual requirements that your vendors have embedded supply chain protections into their own acquisition processes.

Start with your vendor risk questionnaires. Ask vendors to describe the specific strategies, tools, and methods they use to protect against supply chain risks during their own procurement and development processes. Targeted questions should cover whether they use tamper-evident packaging for hardware shipments, whether they verify the integrity of third-party components before integration, and whether they maintain a software bill of materials (SBOM) for their products. Ask whether they conduct supply chain risk assessments and how the results inform their acquisition decisions.

Request evidence beyond self-attestation. Vendors should be able to produce a documented supply chain risk management plan, acquisition procedures that reference supply chain protections, and training records showing that personnel involved in procurement understand supply chain threats. Service level agreements and acquisition contracts should contain explicit language addressing counterfeit component prohibitions and documentation protection requirements.

Watch for red flags in vendor responses. Vendors who can’t articulate specific supply chain protections beyond “we follow industry best practices” likely haven’t operationalized SR-05. The absence of an SBOM, the inability to describe their component verification process, or a lack of documented procedures for controlled distribution all signal gaps. Similarly, vendors who rely solely on upstream supplier certifications without conducting their own assessments present elevated risk.

Verification should go beyond the initial assessment. Monitor vendors for changes in their supply chain practices, particularly after mergers, acquisitions, or shifts in their own supplier base. Review updated documentation annually and incorporate supply chain risk triggers into your continuous monitoring program. Where feasible, conduct periodic on-site or virtual assessments focused specifically on acquisition controls, component integrity verification, and the vendor’s own supplier oversight practices.

Evidence examples

Evidence TypeExample Artifact
Supply chain risk management policy and planDocumented policy defining the organization’s approach to identifying, assessing, and mitigating supply chain risks, including roles, responsibilities, and escalation procedures
Acquisition and procurement proceduresProcedures detailing how supply chain protections are integrated into the acquisition process, including solicitation requirements, purchase order reviews, and contract clauses
Solicitation and contract documentationSolicitation documents, purchase orders, and acquisition contracts containing explicit provisions for tamper-evident packaging, counterfeit component prohibitions, and controlled distribution requirements
Service level agreementsSLAs with suppliers and service providers that include supply chain security requirements, documentation protection clauses, and incident notification obligations
Supply chain risk assessment resultsCompleted risk assessments evaluating specific suppliers, components, or services, with findings that inform acquisition strategy decisions
Training and awareness recordsDocumentation of training, education, and awareness programs for procurement and security personnel covering supply chain threats, mitigation strategies, and activation criteria
System security and privacy plansSecurity and privacy plans that address how supply chain risk management integrates with the organization’s broader information security and privacy programs

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.20 Addressing information security within supplier agreementsPartial
ISO 27001:20225.21 Managing information security in the ICT supply chainPartial
ISO 27001:20225.23 Information security for use of cloud servicesPartial
NIST SP 800-171 Rev 303.17.02 Acquisition Strategies, Tools, and MethodsPartial
  • AT-03 — Role-based Training: Ensures personnel involved in acquisition and procurement receive targeted training on supply chain risks and mitigation strategies.
  • SA-02 — Allocation of Resources: Determines funding and staffing for supply chain risk management activities within the acquisition lifecycle.
  • SA-03 — System Development Life Cycle: Integrates supply chain protections into the broader system development process from design through deployment.
  • SA-04 — Acquisition Process: Establishes the foundational procurement framework into which SR-05’s supply chain strategies and tools are embedded.
  • SA-05 — System Documentation: Requires vendors to provide documentation sufficient for organizations to verify supply chain integrity claims.
  • SA-08 — Security and Privacy Engineering Principles: Applies secure design principles to acquired components, reducing the attack surface introduced by third-party products.
  • SA-09 — External System Services: Governs how organizations manage risk when relying on external service providers whose supply chains may introduce vulnerabilities.
  • SA-10 — Developer Configuration Management: Ensures that vendors maintain configuration control over their build environments, preventing unauthorized modifications like those seen in the SolarWinds compromise.
  • SA-15 — Development Process, Standards, and Tools: Requires that development tools and environments used by suppliers meet defined security standards.
  • SR-06 — Supplier Assessments and Reviews: Complements SR-05 by establishing the assessment and review processes used to evaluate supplier supply chain practices.

Frequently asked questions

What is NIST SP 800-53 SR-05?

SR-05 requires organizations to employ specific acquisition strategies, tools, and methods to protect against, identify, and mitigate supply chain risks. These protections address threats like counterfeiting, tampering, insertion of malicious software, and poor development practices at suppliers. The control applies across LOW, MODERATE, and HIGH baselines, making it a foundational requirement for any organization subject to NIST SP 800-53.

What happens if SR-05 is not implemented?

Without SR-05, organizations lack structured protections in their procurement processes, leaving them vulnerable to supply chain compromises. An attacker could introduce counterfeit components or inject malicious code through a trusted vendor’s software update, as demonstrated by the SUNBURST backdoor delivered through SolarWinds Orion updates. The absence of tamper-evident packaging requirements, controlled distribution channels, and supplier training programs means threats may go undetected until a breach occurs.

How do you audit SR-05?

Auditors assess SR-05 by examining whether documented acquisition procedures incorporate supply chain risk protections and whether those protections are actively applied during procurement. Specific evidence includes solicitation documentation with supply chain security clauses, acquisition contracts prohibiting tainted or counterfeit components, and training records for personnel responsible for procurement decisions. Auditors also verify that supply chain risk assessment results inform the selection of acquisition strategies, tools, and methods.

What are examples of supply chain acquisition strategies in NIST 800-53?

Supply chain acquisition strategies under SR-05 include obscuring the end use of a system or component, using blind or filtered buys to prevent targeting, and requiring tamper-evident packaging for hardware shipments. Organizations can also restrict purchases from untrustworthy suppliers, use trusted distribution channels, and provide incentives for suppliers who implement security controls and promote transparency. The results of a supply chain risk assessment guide which combination of strategies, tools, and methods an organization deploys.

Experience superior visibility and a simpler approach to cyber risk management