Cyberstudy
PDF p.40 In progress

Supply Chain Attack Surface

Open PDF at p.40 22 flashcards

Summary

PDF p.40

A supply chain encompasses the entire process of designing, manufacturing, and distributing goods and services. Threat actors may infiltrate targets via their supply chains, making procurement management crucial for ensuring reliable sources of equipment and software.

In plain words

Supplementary — not from your PDF

You can be attacked through the companies you buy from or outsource to, such as suppliers, vendors and managed service providers. Every link in the chain has to be trustworthy.

Detailed explanation

PDF p.40
  • Supply Chain
    • Definition: End-to-end process of designing, manufacturing, and distributing goods and services.
    • Infiltration: Threat actors may target companies within the supply chain rather than the primary target directly (e.g., Target data breach via a vendor).
  • Procurement Management
    • Definition: Ensuring reliable sources of equipment and software.
    • Relationships
      • Supplier: Sells products in bulk to businesses (B2B).
      • Vendor: Sells products to retail businesses (B2B) or directly to customers (B2C), may add customization and support.
      • Business Partner: Close relationship with aligned goals and marketing opportunities.
  • Supply Chain Complexity
    • Example: A motherboard's supply chain includes chip manufacturers, firmware developers, OEM resellers, couriers, and administrative staff.
    • Trustworthiness: Each link in the supply chain must be trustworthy to prevent backdoor access.
  • Securing the Supply Chain
    • Trusted Supply Chain: Denying malicious actors the time or resources to modify assets.
    • Reputable Vendors: Best practical effort for most businesses.
    • Scrutiny: Greater scrutiny by government, military/security services, and large enterprises.
    • Secondhand Machines: Particular care needed.
  • Managed Service Providers (MSPs)
    • Definition: Provision and support of IT resources (networks, security, web infrastructure).
    • Outsourcing: Useful for cost-effective and reliable IT provision.
    • Security Complexity: Difficult to monitor MSPs; employees are potential insider threats.

Important terms

taken from the text above
Supply Chain
End-to-end process of designing, manufacturing, and distributing goods and services.
Infiltration
Threat actors may target companies within the supply chain rather than the primary target directly (e.g., Target data breach via a vendor).
Procurement Management
Ensuring reliable sources of equipment and software.
Supplier
Sells products in bulk to businesses (B2B).
Vendor
Sells products to retail businesses (B2B) or directly to customers (B2C), may add customization and support.
Business Partner
Close relationship with aligned goals and marketing opportunities.
Trustworthiness
Each link in the supply chain must be trustworthy to prevent backdoor access.
Trusted Supply Chain
Denying malicious actors the time or resources to modify assets.
Reputable Vendors
Best practical effort for most businesses.
Scrutiny
Greater scrutiny by government, military/security services, and large enterprises.
Secondhand Machines
Particular care needed.
Managed Service Providers (MSPs)
Provision and support of IT resources (networks, security, web infrastructure).
Outsourcing
Useful for cost-effective and reliable IT provision.
Security Complexity
Difficult to monitor MSPs; employees are potential insider threats.
MSPs Managed Service Providers

Examples & real-world scenarios

Supplementary — not from your PDF
  • An attacker gets into a retailer through a heating contractor's network access.
  • Tampered hardware somewhere between the manufacturer and the buyer.
  • A managed service provider whose admin tools reach many customers.

Scenario

A small IT provider manages 50 client networks with one remote-management tool. If the provider is compromised, all 50 clients are exposed. Clients should limit its access and monitor what it does.

Common mistakes

Supplementary — not from your PDF
  • Assuming a trusted vendor's access doesn't need monitoring.
  • Forgetting second-hand equipment when thinking about supply chain risk.

Practical skills

Supplementary — not from your PDF
  • List questions to ask a supplier or MSP about their security.

What I should remember

Key Points PDF p.40
  • Supply Chain
    • Definition: End-to-end process.
    • Infiltration: Via supply chain companies.
  • Procurement Management
    • Relationships: Supplier, vendor, business partner.
  • Supply Chain Complexity
    • Example: Motherboard supply chain.
    • Trustworthiness: Preventing backdoor access.
  • Securing the Supply Chain
    • Trusted Supply Chain: Denying modification opportunities.
    • Reputable Vendors: Practical effort.
    • Scrutiny: Government and large enterprises.
    • Secondhand Machines: Care needed.
  • Managed Service Providers (MSPs)
    • Definition: IT resource provision.
    • Outsourcing: Cost-effective, reliable.
    • Security Complexity: Monitoring challenges, insider threats.