Why: Knowing what vendors and components bring into the plant is the risk knowledge a supply chain risk management plan documents and governs — the practice generates the assessments, vendor facts, and decisions the plan is written from.
What this does not claim: A plan is authored governance the practice does not produce: development, a defined review frequency, and protection from disclosure are their own obligations. The requirement's scope also spans the full system lifecycle — development through disposal, IT services included — where this practice's center of gravity is plant procurement and operations.
- Record vendor and component risk decisions in a form the plan can incorporate
- Surface supplier changes — acquisitions, end-of-life notices, incidents — to the plan owner as review triggers
- Vendor risk assessments feeding the plan
- Review-trigger records connecting supplier events to plan updates
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06