NIST 800-53 REV 5 • SYSTEM AND SERVICES ACQUISITION

SA-19(4)Anti-counterfeit Scanning

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

Use automated scanning tools to detect counterfeit components during receiving inspection. Automated scanning is more consistent and thorough than visual inspection alone.

Example 1: For critical hardware components, use electronic testing equipment to verify component authenticity: X-ray inspection for circuit boards, firmware extraction and comparison for embedded systems, and automated serial number verification against manufacturer databases.

Example 2: For software components, automate authenticity verification: validate digital signatures against the publisher's known signing certificate, verify file hashes against the vendor's published checksums, and scan binaries for known malware signatures before deployment. Integrate these checks into your automated deployment pipeline.