首页> 外文期刊>Computers & Security >Beware suppliers bearing gifts!: Analysing coverage of supply chain cyber security in critical national infrastructure sectorial and cross-sectorial frameworks
【24h】

Beware suppliers bearing gifts!: Analysing coverage of supply chain cyber security in critical national infrastructure sectorial and cross-sectorial frameworks

机译:谨防供应商承载礼品!:在关键的国家基础设施扇形和跨部门框架中分析供应链网络安全的覆盖范围

获取原文
获取原文并翻译 | 示例

摘要

Threat actors are increasingly targeting extended supply chains and abusing client-supplier trust to conduct third-party compromise. Governments are concerned about targeted attacks against critical national infrastructures, where compromise can have significant adverse national consequences. In this paper we identify and review advice and guidance offered by authorities in the UK, US, and the EU regarding Cyber Supply Chain Risk Management (C-SCRM). We then conduct a review of sector specific guidance in the three regions for the chemical, energy, and water sectors. We assessed frameworks that each region's sector offered organisations for C-SCRM suitability. Our results found a range of interpretations for "Supply Chain" that resulted in a diversity in the quantity and quality of advice offered by regional authorities, sectors, and their frameworks. This is exacerbated by the lack of a common taxonomy to support supply chain procurement and risk management that has led to limited coverage in most C-SCRM programs. Our results highlight the need for a taxonomy regarding C-SCRM and systematic guidance (both general and sector specific) to enable controls to be deployed to mitigate against supply chain risk. We provide an outline taxonomy based on our data analysis to promote further discussion and research.
机译:威胁演员越来越多地定向扩展供应链和滥用客户 - 供应商信托,以进行第三方妥协。政府担心针对关键国家基础设施的有针对性的攻击,妥协可能会产生重大的不利国家后果。在本文中,我们识别和审查英国,美国和欧盟有关网络供应链风险管理(C-SCRM)的咨询和指导。然后,我们对化学,能源和水部门的三个地区进行了对特定指导的审查。我们评估了每个地区的部门为C-SCRM适用性提供的组织提供的框架。我们的成果为“供应链”发现了一系列解释,导致区域当局,部门及其框架提供的咨询的数量和质量多样化。这加剧了缺乏常见分类,以支持供应链采购和风险管理导致大多数C-SCRM计划的覆盖率有限。我们的结果强调了对C-SCRM和系统指导(一般和部门特定的系统指导)的分类需要,以使能够部署控制以减轻供应链风险。我们根据我们的数据分析提供了概述分类学,以促进进一步讨论和研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号