Diverse Supply Base
Supply Chain Risk Management
NIST Control Text
Employ a diverse set of sources for the following system components and services: [Assignment: organization-defined system components and services].
NIST Discussion
Diversifying the supply of systems, system components, and services can reduce the probability that adversaries will successfully identify and target the supply chain and can reduce the impact of a supply chain event or compromise. Identifying multiple suppliers for replacement components can reduce the probability that the replacement component will become unavailable. Employing a diverse set of developers or logistics service providers can reduce the impact of a natural disaster or other supply chain event. Organizations consider designing the system to include diverse materials and components.
SL5 Supplemental Guidance
Apply SP 800-161 Rev 1 guidance [3] for diversifying the supply base to eliminate single points of failure, particularly for critical components where feasible. Where market constraints limit supplier diversity, apply compensating supply chain risk mitigations.