{"data":{"id":"SR-04","name":"Provenance","family":"SR","family_name":"Supply Chain Risk Management","withdrawn":false,"description":"Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [Assignment: organization-defined systems, system components, and associated data].","supplemental_guidance":"Every system and system component has a point of origin and may be changed throughout its existence. Provenance is the chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include personnel and processes used to interact with or make modifications to the system, component, or associated data. Organizations consider developing procedures (see SR-01) for allocating responsibilities for the creation, maintenance, and monitoring of provenance for systems and system components; transferring provenance documentation and responsibility between organizations; and preventing and monitoring for unauthorized changes to the provenance records. Organizations have methods to document, monitor, and maintain valid provenance baselines for systems, system components, and related data. These actions help track, assess, and document any changes to the provenance, including changes in supply chain elements or configuration, and help ensure non-repudiation of provenance information and the provenance change records. Provenance considerations are addressed throughout the system development life cycle and incorporated into contracts and other arrangements, as appropriate.","enhancements":[{"id":"SR-04(01)","name":"Identity","statement":"Establish and maintain unique identification of the following supply chain elements, processes, and personnel associated with the identified system and critical system components: [Assignment: organization-defined supply chain elements, processes, and personnel associated with organization-defined systems and critical system components].","baselines":[]},{"id":"SR-04(02)","name":"Track and Trace","statement":"Establish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [Assignment: organization-defined systems and critical system components].","baselines":[]},{"id":"SR-04(03)","name":"Validate as Genuine and Not Altered","statement":"Employ the following controls to validate that the system or system component received is genuine and has not been altered: [Assignment: organization-defined controls].","baselines":[]},{"id":"SR-04(04)","name":"Supply Chain Integrity — Pedigree","statement":"Employ [Assignment: organization-defined controls] and conduct [Assignment: organization-defined analysis] to ensure the integrity of the system and system components by validating the internal composition and provenance of critical or mission-essential technologies, products, and services.","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SR-04","name":"Provenance","description":"Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [Assignment: organization-defined systems, system components, and associated data].","discussion":"Every system and system component has a point of origin and may be changed throughout its existence. Provenance is the chronology of the origin, development, ownership, location, and changes to a system or system component and associated data. It may also include personnel and processes used to interact with or make modifications to the system, component, or associated data. Organizations consider developing procedures (see SR-01) for allocating responsibilities for the creation, maintenance, and monitoring of provenance for systems and system components; transferring provenance documentation and responsibility between organizations; and preventing and monitoring for unauthorized changes to the provenance records. Organizations have methods to document, monitor, and maintain valid provenance baselines for systems, system components, and related data. These actions help track, assess, and document any changes to the provenance, including changes in supply chain elements or configuration, and help ensure non-repudiation of provenance information and the provenance change records. Provenance considerations are addressed throughout the system development life cycle and incorporated into contracts and other arrangements, as appropriate.","related_controls":["CM-08","MA-02","MA-06","RA-09","SA-03","SA-08","SI-04"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":true,"changes_from_rev4":"New control family introduced in Rev 5"}},"compliance_mappings":{"iso_27001_2022":["A.5.21","A.8.30"],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["ID.RA-09"],"cis_controls_v8":["CIS 16.4","CIS 16.5","CIS 16.11"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.7.5"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.42","SecNumCloud.16.1"],"osfi_b13":["B-13.4.1"],"finma_circular":["V(109)","V(110)"],"gdpr":["Art.28(3)(a)","Art.28(3)(h)"],"dora":["Art.28(5)","Art.30(2)(a)"],"bio2":[],"rbi_csf":[],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.II.1"],"swift_cscf":[],"cbb_tm":["TM-15"],"qatar_nia":["SD"],"uae_ia":["T10"],"bot_cyber":["Ch5.1"],"ffiec_is":["II.C.14"],"iosco_cyber":["PROT-7"],"sebi_cscrf":["PR.AS"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.9.2"],"fda_21_cfr_11":[],"fda_cyber":["524B-1","SBOM-1","SBOM-2","SBOM-3","ST-4"],"hitrust_csf":["05.b"],"iso_27799":[],"lloyds_ms":["MS8.8"],"naic_ds":[],"nhs_dspt":["NDG-10.1","NDG-10.4"],"pra_ss1_23":[],"solvency_ii":["DR.272","EIOPA-Cloud-GL3"],"owasp_masvs_v2":[],"csa_ccm_v4":["TVM-05"],"csa_aicm":["TVM-05"],"ccss_v9":[],"mica":["Art.66(3)"],"basel_sco60":["SCO60.54"],"bssc":["NOS-02"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Provenance tracking that validates data origin and lineage at system boundaries enables detection of exfiltration over C2 channels by identifying data being transmitted that does not match authorized data flow origins."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Supply chain provenance controls that track data lineage and validate authorized data transfer pathways enable detection of exfiltration over alternative protocols by flagging data leaving through uncharacterized channels."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Provenance tracking for data movement to physical media—including chain-of-custody documentation and data classification enforcement—limits exfiltration by ensuring physical media transfers are authorized and traceable."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Provenance verification of software components—including vendor validation, SBOM analysis, and supply chain attestation—directly detects supply chain compromise by identifying components with unverified or suspicious origins."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Provenance validation of server software components—verifying publisher identity, code signing, and distribution chain integrity—detects unauthorized server components that adversaries install for persistent backdoor access."},{"id":"T1554","name":"Compromise Host Software Binary","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Software binary provenance checking through hash verification, code signing validation, and integrity attestation detects compromise of host software binaries by identifying executables that deviate from their verified origin."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Provenance controls that track data classification and authorized export channels enable detection of exfiltration over web services by identifying sensitive data being uploaded to unauthorized cloud destinations."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Firmware provenance verification—including manufacturer attestation, signed image validation, and supply chain documentation—detects unauthorized system image modifications by comparing deployed firmware against verified baselines."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Provenance tracking identifying unauthorized encrypted data transfers to external destinations enables detection of exfiltration over asymmetric encrypted non-C2 protocols by flagging data leaving through uncharacterized paths."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Data provenance controls that validate authorized cleartext data transfers enable detection of exfiltration over unencrypted protocols by identifying sensitive data flowing through channels without proper authorization."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Provenance tracking for USB data transfers—including device inventory, data classification enforcement, and transfer logging—enables detection of USB exfiltration by identifying unauthorized data movement to removable devices."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Provenance validation of AppleScript sources and automation workflows detects adversary execution by identifying scripts that did not originate from approved development pipelines or authorized automation frameworks."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Provenance verification of software dependencies—including package source validation, dependency pinning, and SBOM attestation—directly detects compromised development tools and poisoned library dependencies."},{"id":"T1195.002","name":"Compromise Software Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Supply chain provenance controls that verify software distribution integrity—including build reproducibility, signed releases, and distribution chain validation—detect software supply chain compromise at the delivery stage."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Hardware provenance tracking—including manufacturer verification, tamper-evident packaging, and component attestation—detects hardware supply chain compromise by validating the origin and integrity of physical components."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Container image provenance validation—including registry source verification, image signing, and build attestation—prevents execution of malicious container images by ensuring only images with verified origins are deployed."},{"id":"T1505.001","name":"SQL Stored Procedures","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Provenance verification of SQL stored procedures—including code review attestation and deployment pipeline validation—detects adversary-implanted procedures by identifying database code with unverified origins."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Provenance validation of Exchange transport agents through publisher verification and code signing detects adversary-installed agents by identifying transport components that did not originate from approved sources."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Provenance verification of IIS components—including module signing validation and deployment pipeline attestation—detects adversary-installed web server components by identifying modules with unverified origins."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Provenance validation of Mach-O binaries for unauthorized LC_LOAD_DYLIB additions detects adversary persistence by identifying dynamic library loading directives that were not present in the original verified binary."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Firmware provenance verification through manufacturer attestation and signed image validation detects adversary-patched system images by comparing deployed firmware hashes against vendor-certified baselines."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Provenance tracking of firmware version history and manufacturer release records detects system image downgrades by identifying when deployed firmware versions do not match the currently approved release."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-02: iso_27001_2022 clauses taken from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR, v1.0.0). OSA had none. 2026-10-03: statement, discussion and related controls taken from NIST SP 800-53 Release 5.2.0, which this file lacked.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-012","SP-028","SP-040","SP-041","SP-042","SP-050"]}}