The document discusses supply chain risk management (SCRM) and outlines its goals of ensuring sourced hardware and software products are functional and secure. SCRM encompasses five categories of risk related to malicious or counterfeit components, production disruptions, unqualified suppliers, and vulnerabilities. The key outcome of SCRM is guaranteeing products only do their intended functions. SCRM is implemented through security controls and a formal process to analyze and prioritize risks through defense in depth. The aim of SCRM is to fully understand risks when making sourcing decisions.