1
1

00:00:00,510  -->  00:00:02,730
<v Narrator>Supply chain assessment.</v>
2

2

00:00:02,730  -->  00:00:04,320
In this lesson, we're going to talk
3

3

00:00:04,320  -->  00:00:07,200
about supply chain assessment and why it's so important.
4

4

00:00:07,200  -->  00:00:09,150
When you think about supply chain assessment,
5

5

00:00:09,150  -->  00:00:11,970
and more largely, supply chain management,
6

6

00:00:11,970  -->  00:00:13,800
you have to think about all the components
7

7

00:00:13,800  -->  00:00:15,840
that go into a particular product.
8

8

00:00:15,840  -->  00:00:18,597
So for example, when I buy something off the shelf
9

9

00:00:18,597  -->  00:00:21,000
and I get something like a router or a switch,
10

10

00:00:21,000  -->  00:00:23,880
there are hundreds of different pieces inside of that,
11

11

00:00:23,880  -->  00:00:25,920
and each of those pieces could have been tampered
12

12

00:00:25,920  -->  00:00:27,540
with by somebody along the way.
13

13

00:00:27,540  -->  00:00:29,212
By conducting a supply chain assessment,
14

14

00:00:29,212  -->  00:00:30,990
you're going to be able to understand
15

15

00:00:30,990  -->  00:00:32,520
where those parts come from
16

16

00:00:32,520  -->  00:00:34,980
and can you trust that end product.
17

17

00:00:34,980  -->  00:00:36,270
Now, I'm not saying you need to go
18

18

00:00:36,270  -->  00:00:38,280
down to the individual component here,
19

19

00:00:38,280  -->  00:00:40,650
but you do have to understand where do the devices
20

20

00:00:40,650  -->  00:00:41,790
that you're putting into your network
21

21

00:00:41,790  -->  00:00:43,950
come from and can you trust them?
22

22

00:00:43,950  -->  00:00:46,353
After all, we're trying to conduct secure working
23

23

00:00:46,353  -->  00:00:48,480
in an unsecure environment,
24

24

00:00:48,480  -->  00:00:50,250
and this involves mitigating the risks
25

25

00:00:50,250  -->  00:00:51,960
that are caused by the supply chain.
26

26

00:00:51,960  -->  00:00:54,420
Now, to create a trusted computing environment,
27

27

00:00:54,420  -->  00:00:56,100
an organization really has to ensure
28

28

00:00:56,100  -->  00:00:58,200
that the operation of every element,
29

29

00:00:58,200  -->  00:01:00,330
which includes the hardware, the firmware,
30

30

00:01:00,330  -->  00:01:03,540
the drivers, the operating systems, and the applications
31

31

00:01:03,540  -->  00:01:06,060
are all consistent and tamper-resistant.
32

32

00:01:06,060  -->  00:01:07,140
If you can do that,
33

33

00:01:07,140  -->  00:01:09,990
you'll have created a trusted computing environment.
34

34

00:01:09,990  -->  00:01:11,340
Now, in some organizations,
35

35

00:01:11,340  -->  00:01:12,870
this is really, really important.
36

36

00:01:12,870  -->  00:01:15,150
In others, it's not nearly as important.
37

37

00:01:15,150  -->  00:01:16,740
And so this is going to be one of those things
38

38

00:01:16,740  -->  00:01:18,768
that the risk appetite of your organization
39

39

00:01:18,768  -->  00:01:20,656
is going to define how much time,
40

40

00:01:20,656  -->  00:01:23,970
effort, and resources you put into this concept
41

41

00:01:23,970  -->  00:01:25,628
of supply chain assessment.
42

42

00:01:25,628  -->  00:01:27,570
Now, when you get a new vendor,
43

43

00:01:27,570  -->  00:01:29,640
you should conduct due diligence.
44

44

00:01:29,640  -->  00:01:31,830
Now, due diligence is a legal principle
45

45

00:01:31,830  -->  00:01:33,930
that says the subject has used best practice
46

46

00:01:33,930  -->  00:01:36,060
or reasonable care when setting up,
47

47

00:01:36,060  -->  00:01:38,220
configuring and maintaining a system.
48

48

00:01:38,220  -->  00:01:39,840
When you're trying to hire a vendor,
49

49

00:01:39,840  -->  00:01:41,820
you need to ensure that they have done due diligence
50

50

00:01:41,820  -->  00:01:42,900
on their supply chain,
51

51

00:01:42,900  -->  00:01:45,480
and you need to do your due diligence on them.
52

52

00:01:45,480  -->  00:01:47,010
This includes things like ensuring
53

53

00:01:47,010  -->  00:01:49,772
that their cybersecurity program is properly resourced.
54

54

00:01:49,772  -->  00:01:52,108
You also want to make sure that they have security assurance
55

55

00:01:52,108  -->  00:01:55,440
and risk management processes and programs in place.
56

56

00:01:55,440  -->  00:01:57,180
And by doing this, this will help make sure
57

57

00:01:57,180  -->  00:01:59,100
that they have a valid organization
58

58

00:01:59,100  -->  00:02:01,650
and a way of doing due diligence within themselves.
59

59

00:02:01,650  -->  00:02:02,730
Another thing you want to look at
60

60

00:02:02,730  -->  00:02:04,770
is the product support lifecycle.
61

61

00:02:04,770  -->  00:02:06,840
If you're going to buy a product, you need to make sure
62

62

00:02:06,840  -->  00:02:09,450
that they're going to be able to support it for the long term.
63

63

00:02:09,450  -->  00:02:11,472
For example, if you buy Microsoft Windows,
64

64

00:02:11,472  -->  00:02:13,620
you know that they're going to give you patches
65

65

00:02:13,620  -->  00:02:16,410
and updates and support for a certain amount of time.
66

66

00:02:16,410  -->  00:02:18,090
That's known as its end-of-life date.
67

67

00:02:18,090  -->  00:02:20,130
That's part of the product support lifecycle.
68

68

00:02:20,130  -->  00:02:22,770
If I buy a product from some brand new company,
69

69

00:02:22,770  -->  00:02:24,450
do I know they're going to be around in five years
70

70

00:02:24,450  -->  00:02:26,550
when I have a problem and need them to solve it?
71

71

00:02:26,550  -->  00:02:27,900
This is all things you have to consider
72

72

00:02:27,900  -->  00:02:29,370
as part of your due diligence.
73

73

00:02:29,370  -->  00:02:30,510
Another thing you want to consider,
74

74

00:02:30,510  -->  00:02:32,880
is do they have the proper security controls in place
75

75

00:02:32,880  -->  00:02:34,260
for confidential data?
76

76

00:02:34,260  -->  00:02:35,760
If you're giving them access to your data
77

77

00:02:35,760  -->  00:02:37,749
because they're doing something like software as a service,
78

78

00:02:37,749  -->  00:02:40,230
you want to make sure they have the proper security controls
79

79

00:02:40,230  -->  00:02:43,080
in place to ensure your data remains confidential.
80

80

00:02:43,080  -->  00:02:44,250
Another thing you have to think about,
81

81

00:02:44,250  -->  00:02:46,980
is when things go wrong, will they be there to help you?
82

82

00:02:46,980  -->  00:02:48,660
If you have to conduct an incident response
83

83

00:02:48,660  -->  00:02:50,280
or do forensic investigations,
84

84

00:02:50,280  -->  00:02:52,260
will that company be able to support you
85

85

00:02:52,260  -->  00:02:53,880
and provide you assistance?
86

86

00:02:53,880  -->  00:02:55,830
And finally, we want to think about the general
87

87

00:02:55,830  -->  00:02:57,750
and historical company information.
88

88

00:02:57,750  -->  00:02:59,880
When you look at a company, do they have strong enough
89

89

00:02:59,880  -->  00:03:01,980
financials that they're going to be in business next year
90

90

00:03:01,980  -->  00:03:03,300
to support your needs?
91

91

00:03:03,300  -->  00:03:05,430
Or are they going to be a fly-by-night organization
92

92

00:03:05,430  -->  00:03:08,040
that's out of business in the next six to 12 months?
93

93

00:03:08,040  -->  00:03:09,402
These are all things you want to consider
94

94

00:03:09,402  -->  00:03:11,520
as you're doing your due diligence.
95

95

00:03:11,520  -->  00:03:13,170
Now, your due diligence should apply
96

96

00:03:13,170  -->  00:03:16,170
not only to your suppliers, but also to your contractors.
97

97

00:03:16,170  -->  00:03:19,020
If I'm going to hire people to work on my team as contractors,
98

98

00:03:19,020  -->  00:03:20,790
I need to do due diligence on them
99

99

00:03:20,790  -->  00:03:22,440
and make sure I can trust them.
100

100

00:03:22,440  -->  00:03:24,180
Now, another area that we have to start talking
101

101

00:03:24,180  -->  00:03:27,180
about is this concept of the hardware itself.
102

102

00:03:27,180  -->  00:03:28,140
I mentioned earlier,
103

103

00:03:28,140  -->  00:03:30,300
you have to think about where does this hardware come from?
104

104

00:03:30,300  -->  00:03:32,010
And based on your organization,
105

105

00:03:32,010  -->  00:03:33,540
you're going to either have more or less
106

106

00:03:33,540  -->  00:03:35,700
of a risk appetite for hardware.
107

107

00:03:35,700  -->  00:03:37,729
Now, one of the organizations that has a very low tolerance
108

108

00:03:37,729  -->  00:03:40,050
or low risk appetite for hardware,
109

109

00:03:40,050  -->  00:03:41,520
is the Department of Defense.
110

110

00:03:41,520  -->  00:03:44,310
And so they created something known as the Trusted Foundry.
111

111

00:03:44,310  -->  00:03:45,480
Now, the Trusted Foundry
112

112

00:03:45,480  -->  00:03:47,880
is a microprocessor manufacturing utility
113

113

00:03:47,880  -->  00:03:50,010
that's part of a validated supply chain,
114

114

00:03:50,010  -->  00:03:52,530
one where the hardware and software does not deviate
115

115

00:03:52,530  -->  00:03:54,120
from its documented function.
116

116

00:03:54,120  -->  00:03:56,130
And again, this was created and operated
117

117

00:03:56,130  -->  00:03:58,665
by the Department of Defense, which is the US military,
118

118

00:03:58,665  -->  00:04:00,780
because if they're going to put a microprocessor
119

119

00:04:00,780  -->  00:04:03,240
to run a jet or a bomb or something like that,
120

120

00:04:03,240  -->  00:04:04,950
they want to make sure it does exactly
121

121

00:04:04,950  -->  00:04:07,470
what it's supposed to do, each and every time.
122

122

00:04:07,470  -->  00:04:09,990
And that's what the Trusted Foundry program is all about.
123

123

00:04:09,990  -->  00:04:12,210
For the exam, you really just need to understand
124

124

00:04:12,210  -->  00:04:14,220
that Trusted Foundry is a way to ensure
125

125

00:04:14,220  -->  00:04:16,920
that microprocessors in the supply chain are secure,
126

126

00:04:16,920  -->  00:04:19,140
and it's run by the Department of Defense.
127

127

00:04:19,140  -->  00:04:20,130
Now, another thing we want to talk
128

128

00:04:20,130  -->  00:04:22,530
about is hardware source authenticity.
129

129

00:04:22,530  -->  00:04:24,480
This is the process of ensuring the hardware
130

130

00:04:24,480  -->  00:04:27,990
is procured tamper-free from trustworthy suppliers.
131

131

00:04:27,990  -->  00:04:29,670
Now, the idea here is we have to know
132

132

00:04:29,670  -->  00:04:31,500
where our stuff comes from.
133

133

00:04:31,500  -->  00:04:33,690
Now, if you need a new router, do you buy it directly
134

134

00:04:33,690  -->  00:04:36,030
from Cisco, from one of their authorized resellers,
135

135

00:04:36,030  -->  00:04:38,700
or do you go on eBay and buy a secondhand one?
136

136

00:04:38,700  -->  00:04:40,380
Well, depending on which way you do,
137

137

00:04:40,380  -->  00:04:43,050
that thing is going to be more or less trustworthy.
138

138

00:04:43,050  -->  00:04:45,420
There is a much greater risk of inadvertently obtaining
139

139

00:04:45,420  -->  00:04:47,229
counterfeited or compromised devices
140

140

00:04:47,229  -->  00:04:50,610
when you purchase from secondhand or aftermarket sources.
141

141

00:04:50,610  -->  00:04:53,760
So whenever possible, go straight to the source.
142

142

00:04:53,760  -->  00:04:55,770
When I look at these routers and switches,
143

143

00:04:55,770  -->  00:04:57,480
just by looking at them, I can't tell
144

144

00:04:57,480  -->  00:04:59,370
if they've been modified on the inside.
145

145

00:04:59,370  -->  00:05:01,860
This is something that can be done inside of those machines.
146

146

00:05:01,860  -->  00:05:04,680
And there's been cases where there has been malware
147

147

00:05:04,680  -->  00:05:07,140
embedded into the firmware of these devices,
148

148

00:05:07,140  -->  00:05:09,840
or extra chips being put inside these devices,
149

149

00:05:09,840  -->  00:05:12,000
and then they're sold at a cheap price online.
150

150

00:05:12,000  -->  00:05:13,710
And that way, you install this,
151

151

00:05:13,710  -->  00:05:15,930
and now they have access to your entire network.
152

152

00:05:15,930  -->  00:05:17,580
So you have to be careful with this stuff,
153

153

00:05:17,580  -->  00:05:20,250
and that is why supply chain assessments are so critical
154

154

00:05:20,250  -->  00:05:21,850
to the security of your network.
