Cybersecurity Reference and Resource Guide

2019 Cybersecurity Resource and Reference Guide_DoD-CIO_Final_2020FEB07

The purpose of this document is to provide a useful reference of both U.S. and International resources, in order to develop cybersecurity programs and to build and maintain strong network protection. Extensive reference materials exist that support efforts to build and operate trusted networks and ensure information systems maintain an appropriate level of confidentiality, integrity, authentication, non-repudiation, and availability. The resources compiled here support security cooperation and shared best practices to help achieve collective cybersecurity goals. This guide provides readily available and unclassified information pertaining to cybersecurity norms, best practices, security cooperation, policies and standards authored and adopted by the United States (U.S.) government, the U.S. Department of Defense (DoD), and recognized international institutes and workforce development training resources provided by government, industry, and academia.

Aspects related to Cyber Supply Chain Risk Management in the document:

Cyber Supply Chain Risk Management (SCRM) is the process of identifying, assessing, and mitigating the risks associated with the distributed and interconnected nature of information and operational technology product and service supply chains. It covers the entire life cycle of a system (including design, development, distribution, deployment, acquisition, maintenance, and destruction) as supply chain threats and vulnerabilities may intentionally or unintentionally compromise an information and operational technology product or service at any stage.

Website: https://csrc.nist.gov/Projects/Supply-Chain-Risk-Management

NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations, April 2015

Federal agencies are concerned about the risks associated with information and communications technology (ICT) products and services that may contain potentially malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the ICT supply chain. These risks are associated with the federal agencies decreased visibility into, understanding of, and control over how the technology that they acquire is developed, integrated, and deployed, as well as the
processes, procedures, and practices used to assure the integrity, security, resilience, and quality of the products and services. This publication provides guidance to federal agencies on identifying, assessing, and mitigating ICT supply chain risks at all levels of their organizations. This publication integrates SCRM into federal agency risk management activities by applying a multi- tiered, SCRM-specific approach, including guidance on supply chain risk assessment and mitigation activities.

Website: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pd

Cybersecurity and Information Systems Digest

Cybersecurity & Information Systems Information Analysis Center (CSIAC)
14 DECEMBER 2021

The Digest is a newsletter intended to provide readers with a greater awareness of the latest research and development trends in the four technical focus areas supported by CSIAC while also highlighting recent CSIAC activities, services, and products.

Find the latest issue at this link:

14 DECEMBER 2021 – CSIAC

Preparing Supply Chain for the Next Disruption Beyond COVID-19: Managerial Antecedents of Supply Chain Resilience

Ethan Nikookar, Yoshio Yanadori

International Journal of Operations & Production Management

Preparing supply chain for the next disruption beyond COVID-19: managerial antecedents of supply chain resilience | Emerald Insight

Article publication date: 10 December 2021

Purpose

COVID-19 once again showed the importance of building resilience in supply chains. Extant research on supply chain resilience management has successfully identified a set of organizational antecedents that contribute to supply chain resilience. However, little is known about the mechanisms by which these antecedents are developed within a firm. Drawing on the dynamic managerial capabilities theory, the current study aims to investigate the critical role that supply chain managers play in developing the organizational antecedents. Specifically, this study shows that supply chain managers’ social capital, human capital and cognition are instrumental to the development of three organizational supply chain resilience antecedents: visibility, responsiveness and flexibility, which subsequently enhance the firm’s supply chain resilience.

The authors employ survey data collected from 598 manufacturing firms in Australia, and Hayes and Preacher’s (2014) parallel multiple mediator model to empirically test the hypotheses.

Findings

The findings of the study establish that supply chain managers’ social capital, human capital and cognition indeed have implications for developing supply chain resilience. Furthermore, the mediators through which managers’ social capital, human capital and cognition improve supply chain resilience are identified in the current study.

Originality/value

The study contributes to the extant literature on supply chain resilience, investigating the role that supply chain managers play in developing the resilience of their firm.

CyberLEO and CyberSatGov

The CyberSat events are dedicated to fostering the necessary discussions to
understand current threat vectors in the satellite and space industry, with the
intent to develop solutions to prioritize and mitigate risks.

MAY 11-13, 2022 | LOS ANGELES, CA
NOV. 1-3, 2022 | RESTON, VA

Based on market demand, CyberLEO will launch in May in Los Angeles, CA and address cybersecurity threats to Low Earth Orbit satellites and emerging technologies. The conversation continues in November with the flagship event CyberSatGov, focusing on
government, military, satellite, and space technologies.

For more information, visit 39937-CyberSat22-Prospectus-Update_2.pdf (cybersatsummit.com)

To register, visit CyberSat 2022 – New Registration (eventscloud.com)

Rocky Mountain Cyberspace Symposium 2022

Rocky Mountain Cyberspace Symposium 2022 (eventsquid.com)

Rocky Mountain Cyberspace Symposium 2022 AFCEA Rocky Mountain Chapter
Mon, February 21, 2022 — Thu, February 24, 2022

The Rocky Mountain Cyberspace Symposium’s theme this year is: “Securing Partnerships and Technologies.” Modern organizations, whether Federal or Commercial, are increasingly interdependent on each other for mission critical pieces of their operations.  Events in late 2020 and early 2021 highlighted some of the risks and vulnerabilities that can come with this dependence.  Whether it is supply chain risk as demonstrated by the SolarWinds hack, or more traditional exploitations like those seen against Microsoft Exchange; as we all increasingly rely on trusted partners for our success, a critical look at existing and new strategies for securing our shared requirements becomes necessary.

Register at the link above by February 24, 2022 @ 12:00 pm

Four New Foreign Companies Added to Department of Commerce Entity List

NSO Group: Israeli spyware company added to US trade blacklist – BBC News

The US Commerce Department’s Bureau of Industry and Security (BIS) has added four foreign companies to its Entity List. The decision comes as these companies – two from Israel, and one each from Russia and Singapore – were deemed to act in a way that went against the national security or foreign policy interests of the United States. NSO Group and Candiru, the two companies from Israel, reported supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers. 

New Law Tightens U.S. Restrictions on Equipment in Supply Chain

Biden signs legislation to tighten U.S. restrictions on Huawei, ZTE | Reuters

New legislation signed in November – The Secure Equipment Act – will prevent companies that are deemed security threats from receiving new equipment licenses from U.S. regulators. The new law requires the Federal Communications Commission (FCC) to no longer review or approve any authorization application for equipment that poses an unacceptable risk to national security.

Commerce Proposes New Software Supply Chain Safety Criteria

Commerce Proposes New Software Supply Chain Safety Criteria – MeriTalk

The Department of Commerce is proposing new safety criteria for connected software to help better secure information and communications technology and services (ICTS) supply chains, including potential third-party audits of connected software and ICTS transactions, according to a proposed rule posted to the Federal Register Nov. 26.

The Department of Commerce is seeking feedback on the rule in its entirety but is also specifically looking for feedback on how to define what is a “reliable third-party” for the purposes of the rule. The agency also wants to know if its criteria of “third-party auditing of connected software applications” is sufficiently descriptive or whether the agency needs to get more specific.

The agency will accept public comment on the proposed rule until Dec. 30.