<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Supply chain a large opportunity for attacks in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Supply-chain-a-large-opportunity-for-attacks/m-p/51013#M3490</link>
    <description>&lt;P&gt;The linked article, leading back to the actual original work cited, is a good example of the challenges of supply chain risk management (SCRM) in the cyber world. As background, I worked on the original, nascent &amp;nbsp;US Defense Department SCRM program when it was still classified as &lt;EM&gt;&lt;A href="https://sgp.fas.org/crs/natsec/R40427.pdf" target="_blank" rel="noopener"&gt;Comprehensive National Cybersecurity Initiative&lt;/A&gt; #11&lt;/EM&gt;. At that time we made the observation, and tried to spread it widely, that in the traditional logistics community supply chain risk is all about risks &lt;STRONG&gt;TO&lt;/STRONG&gt; the supply chain, such as damage, theft, delivery delays, transportation issues, intermediate warehouse problems, etc. Markedly different is supply chain risk in the cyber world, where we are concerned with risks &lt;STRONG&gt;THROUGH&lt;/STRONG&gt; the supply chain. For our world, the focus is on the reality that the supply chain can become a very effective attack vector against most any operational activity.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article John linked to, without listing any of the 'important questions" he alluded to, is a good start on becoming aware of how cyber SCRM has become so complex in the past decade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2022 11:42:16 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2022-05-17T11:42:16Z</dc:date>
    <item>
      <title>Supply chain a large opportunity for attacks</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Supply-chain-a-large-opportunity-for-attacks/m-p/50999#M3488</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Black Asia raises some important questions about supply chain security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.darkreading.com/risk/black-hat-asia-firmware-supply-chain-woes-plague-device-security" target="_blank"&gt;https://www.darkreading.com/risk/black-hat-asia-firmware-supply-chain-woes-plague-device-security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:11:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Supply-chain-a-large-opportunity-for-attacks/m-p/50999#M3488</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Supply chain a large opportunity for attacks</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Supply-chain-a-large-opportunity-for-attacks/m-p/51013#M3490</link>
      <description>&lt;P&gt;The linked article, leading back to the actual original work cited, is a good example of the challenges of supply chain risk management (SCRM) in the cyber world. As background, I worked on the original, nascent &amp;nbsp;US Defense Department SCRM program when it was still classified as &lt;EM&gt;&lt;A href="https://sgp.fas.org/crs/natsec/R40427.pdf" target="_blank" rel="noopener"&gt;Comprehensive National Cybersecurity Initiative&lt;/A&gt; #11&lt;/EM&gt;. At that time we made the observation, and tried to spread it widely, that in the traditional logistics community supply chain risk is all about risks &lt;STRONG&gt;TO&lt;/STRONG&gt; the supply chain, such as damage, theft, delivery delays, transportation issues, intermediate warehouse problems, etc. Markedly different is supply chain risk in the cyber world, where we are concerned with risks &lt;STRONG&gt;THROUGH&lt;/STRONG&gt; the supply chain. For our world, the focus is on the reality that the supply chain can become a very effective attack vector against most any operational activity.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article John linked to, without listing any of the 'important questions" he alluded to, is a good start on becoming aware of how cyber SCRM has become so complex in the past decade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 11:42:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Supply-chain-a-large-opportunity-for-attacks/m-p/51013#M3490</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2022-05-17T11:42:16Z</dc:date>
    </item>
  </channel>
</rss>

