scm.cc / FedRAMP 20x KSIs

KSI-SCR-MON - Supply Chain Risk

Monitoring Supply Chain Risk

Official statement

Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.

The official reference cites no related SP 800-53 controls for this indicator.

Other Supply Chain Risk indicators

Source: https://fedramp.gov/2026/reference/20x/c/key-security-indicators/. Pinned 2026-09-27 (catalog fedramp-20x-ksi/official-1.0.0-cr26). This page shows the list as pinned on that date. A weekly automated check flags any difference from the official page.

All 20x Key Security Indicators