Please use this identifier to cite or link to this item:
https://dair.nps.edu/handle/123456789/5075
Full metadata record
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Michael Bandor, Charles M. Wallen | - |
dc.contributor.author | Carol Woody, Christopher Alberts | - |
dc.date.accessioned | 2024-05-23T19:51:30Z | - |
dc.date.available | 2024-05-23T19:51:30Z | - |
dc.date.issued | 2024-05-01 | - |
dc.identifier.citation | APA | en_US |
dc.identifier.uri | https://dair.nps.edu/handle/123456789/5075 | - |
dc.description | Proceedings paper | en_US |
dc.description.abstract | Increasingly, complex, software-intensive systems rely on software from third parties. However, recent events, such as MoveIT, SolarWinds®, and Log4j™ (Liu, 2021), demonstrate the profound cybersecurity consequences of lax third-party component management. Too often, these components are unknown, and suppliers are only beginning to be incentivized to consider the risk their products pose. For their part, acquirers remain primarily focused on cost and schedule. To help manage these challenges, and to deliver a secure-by-design outcome, the Carnegie Mellon University Software Engineering Institute (SEI) developed the Acquisition Security Framework (ASF). The ASF describes practices needed across the supply chain to reduce risk gaps. In a derivative effort, the SEI also developed the Software Bills of Materials (SBOM) Framework, a set of SBOM practices and process for managing risk. Building and using SBOM requires heightened collaboration between suppliers and acquirers. Achieving effective SBOM results requires planning, tooling, trained staff, measurement, and monitoring, because technology and its use is always changing. Information available from an SBOM can offer insights into the challenges faced by the groups engaged in managing a system. This paper describes both frameworks and the opportunities for improving acquisition cybersecurity risk provided by each. | en_US |
dc.description.sponsorship | ARP | en_US |
dc.language.iso | en_US | en_US |
dc.publisher | Acquisition Research Program | en_US |
dc.relation.ispartofseries | Acquisition Management;SYM-AM-24-031 | - |
dc.subject | cybersecurity | en_US |
dc.subject | SBOM | en_US |
dc.subject | supply chain risk | en_US |
dc.subject | engineering risk | en_US |
dc.title | Improve Acquisition Cybersecurity Risk Using the Acquisition Security Framework and SBOM Risk Framework | en_US |
dc.type | Technical Report | en_US |
Appears in Collections: | Annual Acquisition Research Symposium Proceedings & Presentations |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
SYM-AM-24-031.pdf | 585.05 kB | Adobe PDF | View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.