Part 40 - Information Security and Supply Chain Security

40.000 Scope of part.

(a) This part addresses broad security requirements that apply to acquisitions of products and services. It prescribes policies and procedures for managing information security and supply chain security when acquiring products and services that include, but are not limited to, information and communications technology (ICT).

(b) See part  39 for security-related policies and procedures that only apply to ICT.

(c) See parts 4, 24, and 46 for additional policies and procedures related to managing information security and supply chain security.

(d) Information and supply chain policies and procedures that are unrelated to security are covered in other parts of the FAR ( e.g., part  22 for labor and human trafficking risks and part  23 for climate-related risks).

Subpart 40.1 - [Reserved]

Subpart 40.2 - [Reserved]

Subpart 40.3 - [Reserved]