Skip Links

Network World

Jon Oltsik

Cybersecurity Supply Chain Management

A new and unique perspective on cybersecurity is coming out of the federal space

By joltsik on Wed, 10/28/09 - 4:40pm.

While travelling by train from Boston to NYC, I read two very thought-provoking papers on cybersecurity. Both are about a concept known as the cybersecurity supply chain. At a fundamental level, this thesis states that security is only as good as the whole supply chain process. Therefore, large organization must check the security of their suppliers, the integrity of their products, and the end-to-end systems created by the amalgamation of the piece parts.

I've long preached a similar concept called business process security but the cybersecurity supply chain extends a bit further than my model.

The first paper titled, "Software Supply Chain Integrity Framework," can be downloaded from the SAFECode site (www.safecode.org), an organization dedicated to software assurance composed of Adobe (ADBE), EMC (EMC), Juniper Networks (JNPR), Microsoft (MSFT), Nokia (NOK), SAP (SAP), and Symantec (SYMC).

The second paper titled, "Building a Cyber Supply Chain Assurance Reference Model," can be downloaded from this link (http://www.saic.com/cyber-supply-chain/?intcmp=hs_cybersupplychain) on the SAIC (SAI) site.

Very interesting reading for CISOs or technology vendors working with large organizations of government agencies.

About Networking Nuggets and Security Snippets
Jon Oltsik is a principal analyst at Enterprise Strategy Group responsible for the networking and security services at ESG. Prior to joining ESG, Jon was the founder and principal of Hype-Free Consulting. Mr. Oltsik previously served as VP of Marketing & Strategy at GiantLoop Network where he managed all marketing activities and defined the company’s strategic vision. Jon was also a Senior Analyst at Forrester Research where he covered a wide range of infrastructure and IT topics. In this role, he was frequently quoted in business journals, including the Wall Street Journal, Business Week, and the New York Times, and was also the recipient of a prestigious "best research" award for his breakthrough report, "The Internet Computing Voyage."
 

Most Discussed Posts