Please use this identifier to cite or link to this item:
https://dair.nps.edu/handle/123456789/5432
Full metadata record
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Carol Woody | - |
dc.date.accessioned | 2025-05-13T21:47:58Z | - |
dc.date.available | 2025-05-13T21:47:58Z | - |
dc.date.issued | 2025-05-13 | - |
dc.identifier.citation | APA | en_US |
dc.identifier.uri | https://dair.nps.edu/handle/123456789/5432 | - |
dc.description | SYM Paper | en_US |
dc.description.abstract | Today’s systems are software-intensive and complex, with a growing reliance on third-party technology. Through reuse, systems can be assembled faster with less development cost. Traditionally, systems were hardware-based, and operational risks were primarily linked to reliability. Now systems are largely software-based, which does not wear out like hardware, and the critical risks are different. All software contains vulnerabilities that are hard enough to manage directly. Inheritance through the supply chain increases the management challenges and magnifies the risk of a potential compromise. Attacks on the software supply chain are increasingly frequent and devastating. Software risk management capabilities are brought in too late, if at all, to identify and address software risks that can appear throughout the lifecycle. Extensive compliance rules have been put in place for federal acquisitions to address software and supply chain risk, but there is a noticeable gap in the current acquisition and engineering workforce’s knowledge and skills needed to address the rules effectively. Expanding the knowledge of decision-makers and participants in system acquisition, engineering, and integration are critical activities that are necessary to address the growing software risk. | en_US |
dc.description.sponsorship | Acquisition Research Program | en_US |
dc.language.iso | en_US | en_US |
dc.publisher | Acquisition Research Program | en_US |
dc.relation.ispartofseries | Acquisition Management;SYM-AM-25-421 | - |
dc.subject | software | en_US |
dc.subject | supply chain risk management | en_US |
dc.subject | acquisition lifecycle | en_US |
dc.subject | cybersecurity | en_US |
dc.subject | workforce education | en_US |
dc.title | An Assurance Educated Workforce Is Critical to Addressing Software and Supply Chain Acquisition Lifecycle Risks | en_US |
dc.type | Technical Report | en_US |
Appears in Collections: | Annual Acquisition Research Symposium Proceedings & Presentations |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
SYM-AM-25-421.pdf | SYM Paper | 589.96 kB | Adobe PDF | View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.