sr

Supply Chain Risk Management

9 controls

SR-3(1)

Diverse Supply Base

Apply SP 800-161 Rev 1 guidance [3] for diversifying the supply base to eliminate single points of failure, particularly for critical components where feasible. Where market constraints limit supplier...

View details
SR-3(3)

Sub-Tier Flow Down

Apply SP 800-161 Rev 1 guidance [3] for contractual flow-down of security requirements from prime contractors to relevant sub-tier contractors throughout the supply chain, with due diligence on upstre...

View details
SR-5(2)

Assessments Prior to Selection, Acceptance, Modification, or Update

Organizations assess a sample of AI accelerators before acceptance to verify that hardware security features function as specified: that memory isolation prevents host access, attestation produces val...

View details
SR-6

Supplier Assessments and Reviews

Apply SP 800-161 Rev 1 guidance [3] for rigorous, continuous assessment of all suppliers against consistent baseline criteria evaluating security, integrity, resilience, quality, trustworthiness, and ...

View details
SR-9

Tamper Resistance and Detection

AI accelerators within Weight Enclaves implement comprehensive tamper protection. Sensitive data must exist unencrypted during computation, making the compute cores attractive targets for physical att...

View details
SR-9(1)

Multiple Stages of System Development Life Cycle

Chip providers employ anti-tamper technologies throughout the accelerator development lifecycle, including design, manufacturing, and integration phases. An attacker who can modify the chip during man...

View details
SR-10

Inspection of Systems or Components

Apply SP 800-161 Rev 1 guidance [3] for physical inspection of critical hardware components prior to initial use and periodically thereafter, using techniques such as radiographic examination, materia...

View details
SR-11

Component Authenticity

Apply SP 800-161 Rev 1 guidance [3] for prevention of counterfeit components through use of qualified bidders lists (QBL) and qualified manufacturers lists (QML). While not available to private compan...

View details
SR-13

Supplier Inventory

Apply SP 800-161 Rev 1 guidance [3] for maintaining a comprehensive, criticality-based inventory of all suppliers documenting supplier identities, products provided, and assigned risk levels....

View details