Supply-Chain Risk Management: Incorporating Security into Software Development

被引:0
|
作者
Ellison, Robert J.
Woody, Carol
机构
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As outsourcing and expanded use of commercial off-the-shelf (COTS) products increase, supply-chain risk becomes a growing concern for software acquisitions. Supply-chain risks for hardware procurement include manufacturing and delivery disruptions,(1) and the substitution of counterfeit or substandard components. Software supply-chain risks include third-party tampering with a product during development or delivery, and, more likely, a compromise of the software assurance through the introduction of software defects. This paper describes practices that address such defects and mechanisms for introducing these practices into the acquisition life cycle. The practices improve the likelihood of predictable behavior by systematically analyzing data flows to identify assumptions and using knowledge of attack patterns and vulnerabilities to analyze behavior under conditions that an attacker might create.
引用
收藏
页码:4433 / 4442
页数:10
相关论文
共 50 条
  • [1] Software Supply-Chain Security: Issues and Countermeasures
    Hammi, Badis
    Zeadally, Sherali
    [J]. COMPUTER, 2023, 56 (07) : 54 - 66
  • [2] Supply-Chain Security for Cyberinfrastructure
    Forte, Domenic
    Perez, Ron
    Kim, Yongdae
    Bhunia, Swarup
    [J]. COMPUTER, 2016, 49 (08) : 12 - 16
  • [3] Struggling With Supply-Chain Security
    Viega, John
    Michael, James Bret
    [J]. COMPUTER, 2021, 54 (07) : 98 - 104
  • [4] Supply-chain management
    Trego, L
    [J]. AEROSPACE ENGINEERING, 1997, 17 (1-2) : 3 - 3
  • [5] Supply-chain management
    Thayer, AM
    [J]. CHEMICAL & ENGINEERING NEWS, 1998, 76 (01) : 12 - 16
  • [6] Risk Assessment Framework for Outbound Supply-Chain Management
    Krystofik, Mark
    Valant, Christopher J.
    Archbold, Jeremy
    Bruessow, Preston
    Nenadic, Nenad G.
    [J]. INFORMATION, 2020, 11 (09)
  • [7] Risk assessment framework for outbound supply-chain management
    Krystofik, Mark
    Valant, Christopher J.
    Archbold, Jeremy
    Bruessow, Preston
    Nenadic, Nenad G.
    [J]. Information (Switzerland), 2020, 11 (09):
  • [8] Virtual supply-chain management
    Gunasekaran, A
    Ngai, EWT
    [J]. PRODUCTION PLANNING & CONTROL, 2004, 15 (06) : 584 - 595
  • [9] The supply-chain management effect
    Kopczak, LR
    Johnson, ME
    [J]. MIT SLOAN MANAGEMENT REVIEW, 2003, 44 (03) : 27 - 34
  • [10] Component and application of supply-chain management software for E-Services
    Gao Ge
    Yao Weng
    Wang Tianyong
    [J]. 2006 INTERNATIONAL CONFERENCE ON SERVICE SYSTEMS AND SERVICE MANAGEMENT, VOLS 1 AND 2, PROCEEDINGS, 2006, : 847 - 852