SR-5(2) - Acquisition Strategies, Tools, and Methods | Assessments Prior to Selection, Acceptance, Modification, or Update

Assess the system, system component, or system service prior to selection, acceptance, modification, or update.


ID: SR-5(2)
Enhancement of : SR-5

Space Segment Guidance

Specific missions cannot tolerate parts from vendors without a proven record of secure operations. The acquisition plan limits procurement to manufacturers holding third-party certifications, such as Trusted Foundry or CMMI Level 3 secure-coding accreditation. When the supply base is small, the plan may permit unaccredited vendors only after they pass a tailored security audit conducted by an independent assessor. Document waivers and their compensating controls so the authorizing official can judge residual risk with eyes open.