40.000 Scope of part.
(a) This part addresses broad security requirements that apply to acquisitions of products and services. It prescribes policies and procedures for managing information security and supply chain security when acquiring products and services that include, but are not limited to, information and communications technology (ICT).
(b) See part 39 for security-related policies and procedures that only apply to ICT.
(c) See parts 4, 24, and 46 for additional policies and procedures related to managing information security and supply chain security.
(d) Information and supply chain policies and procedures that are unrelated to security are covered in other parts of the FAR ( e.g., part 22 for labor and human trafficking risks and part 23 for climate-related risks).