C-SCRM (GV.SC)
If you pay attention to cybersecurity news, you’ll have noticed that plenty of cyber risk exists in supply chain management. Third-party software and services are easy targets for organizations as it is still an uncommon practice to explore the cyber risk of vendors. However, software developed by SolarWinds, along with many open source tools such as PyTorch, are susceptible to these types of attacks and we should stay focused on this effort.
As a cyber professional, it is your responsibility to ensure that IT resources that you don’t or can’t control are at least vetted. This vetting process will highlight the vendor’s cyber posture and BCP/DR strategy and will help you gain a better understanding of how the software that you use was developed.
GV.SC-01
This would be the time to assess how you evaluate...