Week 4: Cyber Supply Chain Risk Management

 

 Process and measures to protect against cyberattacks in the supply chain

 

Something I believe we will all will run into at some point Digital supply Chain. What is Digital supply chain? Digital supply chain protects the entire digital ecosystem involved in the movement of goods and information like raw materials leading to finished products. The aspect of supply chain security for digital systems are increasingly used to manage various aspects of the supply chain like order processing, payments and shipping. Cyber supply chain risk management is to identify what cyber risk exist within a chain and manage risks that occur since organizations no longer have control or visibility into the digital supply systems they are connected to. There are three main types of attack, Network, Software, and Hardware supply chain attacks. I won't go over all types of attack but I will talk about one that is the most common and that is Software supply chain attacks. Usually what happens is a vendor's network can be invaded by an attacker who can compromise the vendor's software with malicious code or backdoors to be exploited. When software updates or the customers deploy the compromised software onto their systems, it creates an opportunity for the attacker to steal information and engage in ransomware attacks. Best practice to combat attackers is to have organizations understand the controls that are being used by suppliers and vendors to protect goods or services that are being delivered and create planning stages that include testing and recovery exercises.  

 

Source: https://www.guidepointsecurity.com/education-center/what-is-cyber-supply-chain-risk-management/  

Comments

Popular posts from this blog

Week 3- Attackers Impersonate as Managed Devices

Week 7: Data Privacy