40.000 Scope of part.
Primary source
Verbatim text below is from the Electronic Code of Federal Regulations (eCFR), a public-domain U.S. government work. Always verify the current version with the eCFR before relying on it for any legal matter.
Full Text
(a) This part addresses broad security requirements that apply to acquisitions of products and services. It prescribes policies and procedures for managing information security and supply chain security when acquiring products and services that include, but are not limited to, information and communications technology (ICT).
(b) See part 39 for security-related policies and procedures that only apply to ICT.
(c) See parts 4, 24, and 46 for additional policies and procedures related to managing information security and supply chain security.
e.g.,(d) Information and supply chain policies and procedures that are unrelated to security are covered in other parts of the FAR ( part 22 for labor and human trafficking risks and part 23 for climate-related risks).
This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.