NIST 800-53 REV 5 • SYSTEM AND SERVICES ACQUISITION
SA-19(4) — Anti-counterfeit Scanning
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Practitioner Notes
Use automated scanning tools to detect counterfeit components during receiving inspection. Automated scanning is more consistent and thorough than visual inspection alone.
Example 1: For critical hardware components, use electronic testing equipment to verify component authenticity: X-ray inspection for circuit boards, firmware extraction and comparison for embedded systems, and automated serial number verification against manufacturer databases.
Example 2: For software components, automate authenticity verification: validate digital signatures against the publisher's known signing certificate, verify file hashes against the vendor's published checksums, and scan binaries for known malware signatures before deployment. Integrate these checks into your automated deployment pipeline.