1
00:00:00,090 --> 00:00:01,020
In this lesson,

2
00:00:01,020 --> 00:00:03,180
we're going to cover the different supply chain risks

3
00:00:03,180 --> 00:00:05,610
that you may encounter out in the real world.

4
00:00:05,610 --> 00:00:07,980
In the ever-evolving technology landscape,

5
00:00:07,980 --> 00:00:09,990
understanding and mitigating supply chain risks

6
00:00:09,990 --> 00:00:11,430
is a really big consideration

7
00:00:11,430 --> 00:00:13,170
for cybersecurity professionals.

8
00:00:13,170 --> 00:00:14,730
So, in this lesson,

9
00:00:14,730 --> 00:00:16,680
we're going to focus on the potential vulnerabilities

10
00:00:16,680 --> 00:00:19,530
that can arise at various points within the supply chain,

11
00:00:19,530 --> 00:00:22,470
especially from hardware manufacturers, software developers,

12
00:00:22,470 --> 00:00:23,820
and service providers.

13
00:00:23,820 --> 00:00:26,550
First, let's look at hardware manufacturers.

14
00:00:26,550 --> 00:00:28,748
At the heart of supply chain risk lies the complexities

15
00:00:28,748 --> 00:00:30,810
of product manufacturing.

16
00:00:30,810 --> 00:00:32,220
When you consider buying a product

17
00:00:32,220 --> 00:00:33,480
like a router or a switch,

18
00:00:33,480 --> 00:00:35,400
it becomes really clear and apparent

19
00:00:35,400 --> 00:00:36,780
that they're composed of hundreds

20
00:00:36,780 --> 00:00:38,550
of distinct little components.

21
00:00:38,550 --> 00:00:41,220
Each of these components is sourced from various suppliers,

22
00:00:41,220 --> 00:00:43,140
and they can each be a potential vulnerability

23
00:00:43,140 --> 00:00:44,220
if they're tampered with

24
00:00:44,220 --> 00:00:46,770
or if sourced from untrustworthy vendors.

25
00:00:46,770 --> 00:00:49,020
So to prevent issues with our hardware,

26
00:00:49,020 --> 00:00:50,070
we really need to ensure

27
00:00:50,070 --> 00:00:52,380
that we conduct rigorous supply chain assessments

28
00:00:52,380 --> 00:00:54,270
to trace the origins of our hardware

29
00:00:54,270 --> 00:00:56,250
and to determine the integrity of the components

30
00:00:56,250 --> 00:00:57,690
in our enterprise networks.

31
00:00:57,690 --> 00:00:58,950
The origin of the components

32
00:00:58,950 --> 00:01:00,540
within our network infrastructure

33
00:01:00,540 --> 00:01:03,390
can also define the trustworthiness of the entire device

34
00:01:03,390 --> 00:01:04,260
that we're looking at.

35
00:01:04,260 --> 00:01:06,120
For entities with a minimal risk appetite,

36
00:01:06,120 --> 00:01:07,830
such as the Department of Defense,

37
00:01:07,830 --> 00:01:09,690
measures like the Trusted Foundry program

38
00:01:09,690 --> 00:01:10,770
have been implemented

39
00:01:10,770 --> 00:01:12,480
to ensure that all the hardware being installed

40
00:01:12,480 --> 00:01:15,060
in their networks has undergone a strict check

41
00:01:15,060 --> 00:01:16,350
to ensure they're authentic

42
00:01:16,350 --> 00:01:18,120
and that the microprocessors in them

43
00:01:18,120 --> 00:01:19,830
have been manufactured securely

44
00:01:19,830 --> 00:01:21,720
to perform only their designated functions

45
00:01:21,720 --> 00:01:24,990
without any kind of deviations from the known good baseline.

46
00:01:24,990 --> 00:01:26,610
Another often overlooked risk

47
00:01:26,610 --> 00:01:28,080
is the purchase of additional hardware

48
00:01:28,080 --> 00:01:30,660
from secondary or aftermarket sources.

49
00:01:30,660 --> 00:01:32,640
While these options might be budget friendly,

50
00:01:32,640 --> 00:01:34,050
the risk of acquiring counterfeit

51
00:01:34,050 --> 00:01:36,330
or tampered devices can be pretty high.

52
00:01:36,330 --> 00:01:38,130
These devices may have been tampered with,

53
00:01:38,130 --> 00:01:39,360
and their code could be modified

54
00:01:39,360 --> 00:01:41,490
to include malware like a Trojan,

55
00:01:41,490 --> 00:01:44,400
or they could allow remote access or unauthorized access

56
00:01:44,400 --> 00:01:45,900
into your enterprise networks,

57
00:01:45,900 --> 00:01:49,470
or they could cause all sorts of other operational failures.

58
00:01:49,470 --> 00:01:51,870
Now, our supply chain risks are not confined solely

59
00:01:51,870 --> 00:01:53,550
to the world of hardware though.

60
00:01:53,550 --> 00:01:56,010
This brings us to our second type of supply chain risk,

61
00:01:56,010 --> 00:01:58,650
software developers and software providers.

62
00:01:58,650 --> 00:02:00,210
Often, the risk to our networks

63
00:02:00,210 --> 00:02:01,890
is going to come from the software we purchase

64
00:02:01,890 --> 00:02:04,140
and install onto that enterprise network.

65
00:02:04,140 --> 00:02:06,060
Software developers and software providers

66
00:02:06,060 --> 00:02:08,280
are integral cogs in our supply chains,

67
00:02:08,280 --> 00:02:09,750
and any software that we're going to use

68
00:02:09,750 --> 00:02:11,850
in our modern enterprise networks should be checked

69
00:02:11,850 --> 00:02:14,580
to ensure it's properly licensed, that it's authentic,

70
00:02:14,580 --> 00:02:15,690
and that the software is free

71
00:02:15,690 --> 00:02:17,880
of known vulnerabilities or bugs.

72
00:02:17,880 --> 00:02:19,560
Additionally, the software should be scanned

73
00:02:19,560 --> 00:02:22,020
with a good antivirus or anti-malware solution

74
00:02:22,020 --> 00:02:24,210
to ensure that it's free of any malicious code.

75
00:02:24,210 --> 00:02:26,850
This type of software assessment is a lot easier to conduct

76
00:02:26,850 --> 00:02:28,230
if the software you choose to use

77
00:02:28,230 --> 00:02:30,060
is considered to be open source.

78
00:02:30,060 --> 00:02:31,920
That way, you can review the entire source code

79
00:02:31,920 --> 00:02:33,300
if you need to as well.

80
00:02:33,300 --> 00:02:34,350
But even if you're using

81
00:02:34,350 --> 00:02:37,080
a proprietary piece of software like Microsoft Office,

82
00:02:37,080 --> 00:02:38,790
you can still run some simple scans

83
00:02:38,790 --> 00:02:41,370
and vulnerability assessments against those programs

84
00:02:41,370 --> 00:02:43,260
to ensure that they're not vulnerable to known attacks

85
00:02:43,260 --> 00:02:44,400
by a threat actor.

86
00:02:44,400 --> 00:02:46,290
Now, third, we have service providers

87
00:02:46,290 --> 00:02:49,320
and managed service providers known as MSPs.

88
00:02:49,320 --> 00:02:50,430
These service providers,

89
00:02:50,430 --> 00:02:52,980
especially those offering software as a service,

90
00:02:52,980 --> 00:02:54,810
pose some unique challenges to the security

91
00:02:54,810 --> 00:02:56,550
of our enterprise networks.

92
00:02:56,550 --> 00:02:59,100
When you entrust a service provider to access your data,

93
00:02:59,100 --> 00:02:59,933
how can you ensure

94
00:02:59,933 --> 00:03:01,876
that the information they're getting actually maintains

95
00:03:01,876 --> 00:03:04,530
its confidentiality and integrity?

96
00:03:04,530 --> 00:03:05,670
Are the managed service provider's

97
00:03:05,670 --> 00:03:07,260
cybersecurity protocols robust enough

98
00:03:07,260 --> 00:03:08,940
to protect all of your data?

99
00:03:08,940 --> 00:03:10,920
And in the face of a security breach,

100
00:03:10,920 --> 00:03:12,690
would the service provider be well equipped

101
00:03:12,690 --> 00:03:15,060
to provide the necessary support and cooperation

102
00:03:15,060 --> 00:03:18,150
that you might need to conduct a full scale incident response

103
00:03:18,150 --> 00:03:19,770
or forensic investigation?

104
00:03:19,770 --> 00:03:21,000
These are all of the types of things

105
00:03:21,000 --> 00:03:22,980
that your organization needs to think about

106
00:03:22,980 --> 00:03:24,570
when they're trying to make a risk decision

107
00:03:24,570 --> 00:03:27,660
about whether or not to use one service provider or another.

108
00:03:27,660 --> 00:03:29,970
It's all going to be based on their risk appetite

109
00:03:29,970 --> 00:03:31,920
and understanding the potential ramifications

110
00:03:31,920 --> 00:03:34,350
of a data breach to your organization.

111
00:03:34,350 --> 00:03:37,260
So remember, supply chain risks are multifaceted,

112
00:03:37,260 --> 00:03:38,820
and organizations must approach them

113
00:03:38,820 --> 00:03:40,410
with a holistic strategy.

114
00:03:40,410 --> 00:03:42,120
From the tangibility of hardware

115
00:03:42,120 --> 00:03:44,160
to the intangibility of services,

116
00:03:44,160 --> 00:03:45,960
every aspect has to undergo

117
00:03:45,960 --> 00:03:47,954
a supply chain audit and assessment.

118
00:03:47,954 --> 00:03:49,950
Vendor selection is going to be one

119
00:03:49,950 --> 00:03:51,420
of those really important things,

120
00:03:51,420 --> 00:03:53,700
and it's not just a matter of cost efficiency,

121
00:03:53,700 --> 00:03:56,280
but also, you need to factor in due diligence,

122
00:03:56,280 --> 00:03:58,770
historical performance, and a commitment to security

123
00:03:58,770 --> 00:04:00,480
of the vendor you're considering.

124
00:04:00,480 --> 00:04:02,730
Remember, in the realm of supply chain risk

125
00:04:02,730 --> 00:04:04,470
to your organization's security posture,

126
00:04:04,470 --> 00:04:06,480
you are only as strong as the weakest link

127
00:04:06,480 --> 00:04:07,653
in that supply chain.

