Supply Chain News / eSupply Chain / Risk & Compliance

IT Supply Chain Security Weak at Major U.S. Agencies

According to the U.S. Government Accountability Office (GAO), reliance on a global supply chain introduces multiple risks to federal information systems and underscores the importance of threat assessments and mitigation. In a recent report, supply chain threats are present at various phases of a system’s development life cycle and could create an unacceptable risk to federal agencies. Key supply chain-related threats include:

  • installation of intentionally harmful hardware or software (i.e., containing “malicious logic”);
  • installation of counterfeit hardware or software;
  • failure or disruption in the production or distribution of critical products;
  • reliance on malicious or unqualified service providers for the performance of technical services; and
  • installation of hardware or software containing unintentional vulnerabilities, such as defective code.

These threats can have a range of impacts, including allowing attackers to take control of systems or decreasing the availability of critical materials needed to develop systems. These threats can be introduced by exploiting vulnerabilities that could exist at multiple points in the supply chain.

Examples of such vulnerabilities include acquisition of products or parts from unauthorized distributors; application of untested updates and software patches; acquisition of equipment, software, or services from suppliers without knowledge of their past performance or corporate structure; and use of insecure delivery or storage mechanisms. These vulnerabilities could by exploited by malicious actors, leading to the loss of the confidentiality, integrity, or availability of federal systems and the information they contain.

More information can be found on GAO's website, including a 14 page copy of the report.

Source: GAO
You must login or register in order to post a comment.

Multimedia

Videos

Image Galleries

KC SmartPort Momentum

Kansas City SmartPort Momentum 2013 focused on 3PLs, the issues facing the industry, and the role or logistics in economic development

Podcasts

GT Nexus podcast

Supply chain visibility is an appealing yet elusive capability for most companies. While most recognize the significant benefits that would accrue from comprehensive visibility, few have made it a reality across their global operations. Part of the problem companies seem to have in embracing and implementing visibility is the lack of a comprehensive definition or firm understanding of the transformational potential. In this podcast, World Trade and GT Nexus will discuss the definitions and opportunities as well as how new cloud technology platforms are driving significant value to major companies today.

Speaker: Greg Johnson, Chief Marketing Officer & Co-Founder of GT Nexus

More Podcasts

THE MAGAZINE

World Trade 100 Magazine

WT100 May 2013 cover

2013 May

Check out the May 2013 edition of World Trade WT100!
Table Of Contents Subscribe

Trade Zones

How do you use U.S. Foreign Trade Zones?
View Results Poll Archive

WT100 STORE

world-class-warehousing.gif
World-Class Warehousing and Material Handling, 1st Edition

Filled with proven operational solutions, it will guide managers as they develop a warehouse master plan, one designed to minimize the effects of supply chain inefficiencies as it improves logistics accuracy and inventory management - and reduces overall warehousing expense.

More Products

Clear Seas Research

Clear Seas ResearchWith access to over one million professionals and more than 60 industry-specific publications,Clear Seas Research offers relevant insights from those who know your industry best. Let us customize a market research solution that exceeds your marketing goals.

Smoother Moves Calculator

Pacer Smoother Moves CalculatorPacer has designed a unique and easy-to-use tool to help you determine the potential dollar savings and carbon emission reductions generated by using Pacer intermodal services versus trucking.

STAY CONNECTED