About Us

Read More >>

Briefs

Alert: Securing The Cyber Supply Chain

Nick Hoover | 11/30/09
 (0 ratings) | 0Comments  


SECURITY PROS DRAW A LINE AT THE FIREWALL—what happens “out there” might be beyond their control, but a secure perimeter is intended to protect the data and systems within.  That view, however, fails to take into account the role of developers, vendors, customers, users, and others along the supply chain of IT systems, hardware, and software coming into the enterprise. A new school of practice advocates a more encompassing approach to security that leaves none of those touch points unchecked.

It’s called the cybersecurity supply chain, and, as it sounds, it applies the principles of supply chain management—product assembly and acquisition, data sharing among partners, governance, and more—to the security of IT systems and software. “Organizations need to realize that their borders are porous,” says Jim Lewis, director and senior fellow of the Center for Strategic and International Studies’ technology and public policy program. “We’re no longer living behind a moat. It’s not just how secure you are, but how secure the people you connect with are as well.”

About the Author

Plan Your Upgrade To Windows 7

J. Nicholas Hoover has been a technology scribe for InformationWeek since 2005, variously writing about networking, Microsoft, collaboration and cloud computing before moving into the government beat in 2009. Prior to joining InformationWeek, Nick was a graduate student in journalism at American University, where he was a general assignment intern for the Washington Examiner and news editor of an online magazine at American. He found his reporting itch after blogging about the Iraq War in 2003. 

Be the first one to comment.


Register Now Close

Making the right technology choices is a challenge for IT pros everywhere. Whether it’s sorting through vendor claims, justifying new projects or implementing new systems, there's no substitute for the help and guidance of experienced peers. InformationWeek Reports connects you with thousands of your peers. They’ll help you pick the right technologies, ask the right questions and avoid pitfalls. Registration includes:

  • Thousands of research reports that tell you why and how your peers are adopting emerging technologies. Key annual surveys track how technology use changes from year to year
  • Strategy sessions and best practice reports that help you chart a path for successful technology adoption
  • Salary surveys and professional development guides that help you find and improve your place in the market
  • All written by your most trusted source for information - your peers

Registration Already Registered? Login

Related Reports

Government IT pros face growing threatsand compliance requirements

Cybersecurity Balancing Act

Government IT pros face growing threatsand compliance requirements

Continue Reading >>

Government IT pros are pursuing a more open public enterprise, but system interoperability remains a formidable challenge.

Breaking Down Federal Government Data Silos

Government IT pros are pursuing a more open public enterprise, but system interoperability remains a formidable challenge.

Continue Reading >>

Managing and protecting huge amounts of data is a hot-button issue for many federal agencies. In this InformationWeek Analytics Informed CIO report,we discuss a strategy for being effective stewards of public information.

Informed CIO: 7 Key Issues for Government Backups

Managing and protecting huge amounts of data is a hot-button issue for many federal agencies. In this InformationWeek Analytics Informed CIO report,we discuss a strategy for being effective stewards of public information.

Continue Reading >>

It's time for a shift in thinking away from yesterday's security approaches and toward data-centric protection via technologies like encryption, data loss prevention and strong access controls.

Informed CIO: Cyber Security

It's time for a shift in thinking away from yesterday's security approaches and toward data-centric protection via technologies like encryption, data loss prevention and strong access controls.

Continue Reading >>

Enabling People and Organizations to Harness the Transformative Power of Technology

svn