KSI-SCR-MON - Supply Chain Risk
Monitoring Supply Chain Risk
Official statement
Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.
The official reference cites no related SP 800-53 controls for this indicator.
Other Supply Chain Risk indicators
Source: https://fedramp.gov/2026/reference/20x/c/key-security-indicators/. Pinned 2026-09-27 (catalog fedramp-20x-ksi/official-1.0.0-cr26). This page shows the list as pinned on that date. A weekly automated check flags any difference from the official page.