Supplier Performance Risk System (SPRS)
SPRS is a procurement risk analysis tool for the areas of Price, Item, and Supplier risk. The Price Risk tool compares industry prices to the average price paid by the government. The Item Risk tool flags items identified as high risk (based on critical safety/application or risk of counterfeiting). The Supplier Risk tool scores vendors on DoD-wide contract performance.
Access Control (AC) ensures only authorized users can access systems, limiting their functions based on permissions for security.
Audit and Accountability (AU) ensures system activity is logged and reviewed, enabling tracking, analysis, and accountability for actions
Awareness and Training (AT) ensures personnel are educated on security risks, policies, and procedures, fostering informed decision-making.
Configuration Management (CM) involves establishing, maintaining, and controlling system configurations, ensuring security and consistency throughout the system lifecycle.
Continuous Monitoring (CM) involves ongoing assessment of security controls and system status to detect vulnerabilities and ensure operational integrity.
Identification and Authentication (IA) ensures proper identification and verification of users, processes, or devices before granting system access.
Incident Response (IR) defines procedures for detecting, analyzing, responding to, and recovering from cybersecurity incidents to minimize impact.
Media Protection (MP) ensures the confidentiality, integrity, and availability of media containing sensitive information through proper handling, storage, and disposal.
Physical and Environmental Security (PE) safeguards organizational systems and facilities from physical threats, unauthorized access, and environmental hazards.
Risk Assessment (RA) identifies and evaluates risks to organizational operations, assets, and individuals to guide security measures and decisions.
Security Operations (OP) focuses on monitoring, detecting, and responding to security incidents and managing overall security operations.
System and Communications Protection (SC) ensures the confidentiality, integrity, and availability of systems and their communications, managing security boundaries.