SR-11 Supply Chain Risk Management

Component Authenticity

High Risk Moderate Low Cost

SR-11 requires developing anti-counterfeit policies, means to detect counterfeit components, and reporting mechanisms. Counterfeit optics, power supplies, and software installers remain a real path to instability and backdoors in healthcare networks carrying ePHI.

Control Objective

Detect, prevent, and report counterfeit or modified components through policy, authorized channels, verification tools, and intake inspection for ePHI-impacting systems.

Implementation Guidance

  1. Publish anti-counterfeit policy covering IT and clinical networked equipment.
  2. Maintain authorized supplier/distributor lists.
  3. Verify serials, certificates, and cryptographic signatures where provided.
  4. Use vendor authenticity validation tools.
  5. Quarantine and report counterfeits to vendors/appropriate channels.
  6. Train procurement and receiving staff.
  7. Verify software package signatures before admin use on ePHI systems.
  8. Align with SA-19 if both exist in the catalog.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Counterfeit power supplies in IDF

Failures spike; authenticity checks reveal fakes. SR-11 removes them before they take down clinic access switches.

Fake antivirus USB from conference

Unsigned utility blocked by authenticity rules for admin workstations.

Clone SFP causes CRC errors

Authorized-channel replacement restores stable links for EHR traffic.

Best Practices

  • Authorized channels only for critical gear.
  • Verification at receipt.
  • Signature checks for software.
  • Quarantine and reporting.
  • Staff training.
  • Align SA-19/SR-4.

Common Gaps & Violations

  • Auction-site appliances in production.
  • No serial validation.
  • Ignoring vendor anti-counterfeit alerts.
  • Running unsigned PS1 scripts as SYSTEM on EHR hosts.
  • No reporting of suspects.

Required Documentation

  • Component authenticity policy (SR-11)
  • Authorized distributor lists
  • Verification procedures and tools
  • Quarantine/reporting records
  • Training materials

How to Test & Validate

  1. Sample critical purchases for authorized channel evidence.
  2. Review verification records.
  3. Trace a suspect component report.
  4. Check software signature enforcement sample.
  5. Confirm training for buyers/receivers.

Audit Considerations

Authenticity failures cause both outages and security incidents. SR-11 should be visible in purchasing and receiving — the front door for counterfeits.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(c) Integrity — counterfeit components threaten integrity and availability of ePHI systems.
  • 164.308(a)(1) Risk Analysis — include counterfeit acquisition risk.
  • 164.310(d) Device and Media Controls — control hardware/media introduction.
  • 164.306 Reasonable safeguards — trustworthy components support safeguard effectiveness.

Compliance Tips

  • Enforce authorized reseller flags in the purchasing system.
  • Give receiving a simple authenticity checklist.
  • Subscribe to OEM counterfeit bulletins.

Frequently Asked Questions

Difference between SR-11 and SA-19?

Largely overlapping authenticity goals; implement one anti-counterfeit program mapped to both IDs if present.

Are refurbished devices counterfeit?

Not necessarily — require authorized refurb channels and verification.

Does SR-11 cover drugs or implants?

Focus on information system components; clinical product authenticity has separate regulatory regimes.

References & Resources

  • NIST SP 800-53 Rev. 5 — SR-11
  • Related controls: SA-19, SR-4, PE-16, SR-9, SI-7

Need Help Implementing SR-11?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.