When it comes to supply chain risks, agencies need to know when to hold ‘em, know when to fold ‘em
Summary
Chris DeRusha, the federal chief information security officer, told Senate lawmakers in late September that OMB and the FASC will release new guidance in the coming months to help agencies make better decisions about the risk of technology products and services. An official with GSA’s Office of Governmentwide Policy said in an email to Federal News Network that the strategy focuses on addressing the agency’s cyber risks within its most important information systems and programs, and on improving the capabilities of their workforce. There now are more than 30 different supply chain risk management efforts ongoing from FASC to the National Institute of Standards and Technology to the Defense Department’s Cybersecurity Maturity Model Certification (CMMC) program. Bisceglie said supply chain risk management is well past the “hype cycle.” “We are to the point where things need to be implemented and you are seeing that not just based on the executive orders, but the money being pushed to the Cybersecurity and Infrastructure Security Agency (CISA) and the Commerce Department to actually do something about it,” she said. “It has raised itself in priority, and the pandemic, the multiple examples of ransomware like the [Colonial Pipeline] and SolarWinds, and the problems in the Suez Canal, made this something that is being invested in and that people are responsible for.” GSA’s strategy shows just how implementation could work at one agency.