unified
UC-TPRM-07 — Verify component authenticity, provenance, and integrity
Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-TPRM-07
- title
- Verify component authenticity, provenance, and integrity
- statement
- Document and maintain the provenance of critical systems, components, and data through the supply chain, for example with bills of materials and chain-of-custody records. Apply anti-tamper and anti-counterfeit measures: tamper-resistant and tamper-evident packaging and design, inspection of systems and components at receipt and on indication of tampering, and verification of component authenticity with training and reporting of suspected counterfeits.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SR-4
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-9
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-10
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SR-11
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.21
- coverage
- partial
- delta
- propagation of security requirements through the ICT supply chain via contract control
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-9 — Tamper Resistance and Detection
- framework
- nist-800-53
- control_id
- SR-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-11 — Component Authenticity
- framework
- nist-800-53
- control_id
- SR-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-4 — Provenance
- framework
- nist-800-53
- control_id
- SR-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Provenance and BOM records, chain-of-custody, tamper-evident packaging, receipt inspection, and authenticity verification directly detect counterfeit and tampered hardware and components.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to A.5.21 — Managing information security in the ICT supply chain
- framework
- iso-27001
- control_id
- A.5.21
- coverage
- partial
- delta
- propagation of security requirements through the ICT supply chain via contract control
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity maps_to SR-10 — Inspection of Systems or Components
- framework
- nist-800-53
- control_id
- SR-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- Supply-Chain Integrity & OPSEC Operations operates UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Maintaining provenance and verifying integrity of components and data catches backdoored or malicious third-party libraries and models.