---
kind: "section"
citation: "48 C.F.R. § 40.000"
title: "48"
number: "40.000"
heading: "Scope of part."
url: "https://uscodex.org/cfr/48/40.000"
---

# §40.000. Scope of part.

- (a) **This part addresses broad security requirements that apply to acquisitions of products and services.** It prescribes policies and procedures for managing information security and supply chain security when acquiring products and services that include, but are not limited to, information and communications technology (ICT).
- (b) **See part 39 for security-related policies and procedures that only apply to ICT.**
- (c) See parts [4](/cfr/48/part4.md), [24](/cfr/48/part24.md), and 46 for additional policies and procedures related to managing information security and supply chain security.
- (d) Information and supply chain policies and procedures that are unrelated to security are covered in other parts of the FAR (e.g., [part 22](/cfr/48/part22.md) for labor and human trafficking risks and [part 23](/cfr/48/part23.md) for climate-related risks).

## Notes

### Authority

Authority: 40 U.S.C. 121(c); 10 U.S.C. chapter 4 and 10 U.S.C. chapter 137 legacy provisions (see 10 U.S.C. 3016); and 51 U.S.C. 20113.

### Source

Source: 89 FR 22605, Apr. 1, 2024, unless otherwise noted.
