NIST 800-53 r5 · Controls catalogue · Family SR
SR-7Supply Chain Operations Security
Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: {{ insert: param, sr-07_odp }}.
Last updated: 09 May 2026 03:25 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (7)AI
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 10,204 | OPSEC controls directly protect supply chain information from unauthorized observation or disclosure. |
CWE-284 | Improper Access Control | 4,832 | OPSEC measures enforce access restrictions on sensitive supply-chain data and processes. |
CWE-285 | Improper Authorization | 1,230 | Authorization decisions required by OPSEC prevent unauthorized actors from obtaining supply-chain details. |
CWE-552 | Files or Directories Accessible to External Parties | 540 | Controls ensure files and directories holding supply-chain data are not left accessible to unauthorized actors. |
CWE-922 | Insecure Storage of Sensitive Information | 421 | OPSEC requirements improve handling and storage practices for sensitive supply-chain information. |
CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | 314 | Protecting supply-chain artifacts reduces exposure of sensitive system information outside its intended control sphere. |
CWE-538 | Insertion of Sensitive Information into Externally-Accessible File or Directory | 84 | OPSEC practices stop placement of supply-chain information into locations accessible to external parties. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||