In the Wake of Solar Winds Compromise, CISA and NIST Issue Guidance for Preventing, Defending and Mitigating Software Supply Chain Attacks
Summary
The Cybersecurity & Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) jointly published a new resource as part of their ongoing efforts to promote awareness of, and help organizations defend against, supply chain risks. We have previously written about supply chain risk applicable to Internet of Things (IoT) devices, including recent legislative initiatives to develop standards for government contractors and systems. For example, the December 2020 SolarWinds hack involved a software supply chain attack on an IT management tool, SolarWinds’ Orion platform, in which a foreign threat actor inserted a “backdoor” into routine software updates, which allowed the threat actor to gain access to numerous government and private sector networks. An effective supply chain risk management program can mitigate risk through, among other things, establishing security requirements or controls for software and ICT product suppliers, assessing supplier certifications and component inventory, and ensuring that vendors enforce supply chain security requirements, including through contracts and other safeguards. It is critical, however, that all organizations plan for the cybersecurity of their software and ICT products and services and take reasonable steps to ensure that C-SCRM procedures are in place, and that vulnerabilities are addressed in a timely manner consistent with risk.