PDF p.40
In progress
Supply Chain Attack Surface
Summary
PDF p.40A supply chain encompasses the entire process of designing, manufacturing, and distributing goods and services. Threat actors may infiltrate targets via their supply chains, making procurement management crucial for ensuring reliable sources of equipment and software.
In plain words
Supplementary — not from your PDFYou can be attacked through the companies you buy from or outsource to, such as suppliers, vendors and managed service providers. Every link in the chain has to be trustworthy.
Detailed explanation
PDF p.40-
Supply Chain
- Definition: End-to-end process of designing, manufacturing, and distributing goods and services.
- Infiltration: Threat actors may target companies within the supply chain rather than the primary target directly (e.g., Target data breach via a vendor).
-
Procurement Management
- Definition: Ensuring reliable sources of equipment and software.
-
Relationships
- Supplier: Sells products in bulk to businesses (B2B).
- Vendor: Sells products to retail businesses (B2B) or directly to customers (B2C), may add customization and support.
- Business Partner: Close relationship with aligned goals and marketing opportunities.
-
Supply Chain Complexity
- Example: A motherboard's supply chain includes chip manufacturers, firmware developers, OEM resellers, couriers, and administrative staff.
- Trustworthiness: Each link in the supply chain must be trustworthy to prevent backdoor access.
-
Securing the Supply Chain
- Trusted Supply Chain: Denying malicious actors the time or resources to modify assets.
- Reputable Vendors: Best practical effort for most businesses.
- Scrutiny: Greater scrutiny by government, military/security services, and large enterprises.
- Secondhand Machines: Particular care needed.
-
Managed Service Providers (MSPs)
- Definition: Provision and support of IT resources (networks, security, web infrastructure).
- Outsourcing: Useful for cost-effective and reliable IT provision.
- Security Complexity: Difficult to monitor MSPs; employees are potential insider threats.
Important terms
taken from the text above- Supply Chain
- End-to-end process of designing, manufacturing, and distributing goods and services.
- Infiltration
- Threat actors may target companies within the supply chain rather than the primary target directly (e.g., Target data breach via a vendor).
- Procurement Management
- Ensuring reliable sources of equipment and software.
- Supplier
- Sells products in bulk to businesses (B2B).
- Vendor
- Sells products to retail businesses (B2B) or directly to customers (B2C), may add customization and support.
- Business Partner
- Close relationship with aligned goals and marketing opportunities.
- Trustworthiness
- Each link in the supply chain must be trustworthy to prevent backdoor access.
- Trusted Supply Chain
- Denying malicious actors the time or resources to modify assets.
- Reputable Vendors
- Best practical effort for most businesses.
- Scrutiny
- Greater scrutiny by government, military/security services, and large enterprises.
- Secondhand Machines
- Particular care needed.
- Managed Service Providers (MSPs)
- Provision and support of IT resources (networks, security, web infrastructure).
- Outsourcing
- Useful for cost-effective and reliable IT provision.
- Security Complexity
- Difficult to monitor MSPs; employees are potential insider threats.
MSPs Managed Service Providers
Examples & real-world scenarios
Supplementary — not from your PDF- An attacker gets into a retailer through a heating contractor's network access.
- Tampered hardware somewhere between the manufacturer and the buyer.
- A managed service provider whose admin tools reach many customers.
Scenario
A small IT provider manages 50 client networks with one remote-management tool. If the provider is compromised, all 50 clients are exposed. Clients should limit its access and monitor what it does.
Common mistakes
Supplementary — not from your PDF- Assuming a trusted vendor's access doesn't need monitoring.
- Forgetting second-hand equipment when thinking about supply chain risk.
Practical skills
Supplementary — not from your PDF- List questions to ask a supplier or MSP about their security.
What I should remember
Key Points PDF p.40-
Supply Chain
- Definition: End-to-end process.
- Infiltration: Via supply chain companies.
-
Procurement Management
- Relationships: Supplier, vendor, business partner.
-
Supply Chain Complexity
- Example: Motherboard supply chain.
- Trustworthiness: Preventing backdoor access.
-
Securing the Supply Chain
- Trusted Supply Chain: Denying modification opportunities.
- Reputable Vendors: Practical effort.
- Scrutiny: Government and large enterprises.
- Secondhand Machines: Care needed.
-
Managed Service Providers (MSPs)
- Definition: IT resource provision.
- Outsourcing: Cost-effective, reliable.
- Security Complexity: Monitoring challenges, insider threats.