ISSN No.
0976-5697
Volume 8, No. 5, May-June 2017
International Journal of Advanced Research in Computer Science
RESEARCH PAPER
Available Online at [Link]
Cyber Security Risks and Challenges in Supply Chain
Om Pal Bashir Alam
Ministry of Electronics and Information Technology Department of Computer Engineering,
Electronics Niketan, 6, CGO Complex, New Delhi Jamia Millia Islamia, New Delhi
Abstract: Traditional data security practices are not much helpful if any hardware or software component of the system is built to send the inner
data to outside of the system or leave the back door open for intruders intentionally. This kind of back door entry may be restricted if proper
inspection of the network components, monitoring of supply chain steps, history check of network component suppliers is done properly. To
address the above issues, there is need of standard cyber security practice frameworks, cyber security guidelines in supply chain management to
mitigate the cyber security risks in the supply chain of the network components. In this paper, need of cyber security practice framework,
Strategies, Road Map and solutions to resolve the threats of Cyber security in supply chain are discussed and analyzed.
Keywords: Cyber security in supply chain, Cyber security risks in supply chain, cyber security practices, cyber security risks.
1. INTRODUCTION • Inclusion of faults for causing the interruption in
the normal behavior of the equipment.
In today’s scenario electronic devices are integral part to • Hardware tampering by performing various
everyday life, to the critical infrastructures, and to defense invasive operations
system. These electronics devices are built up through • Through insertion of hidden methods, the normal
semiconductor integrated circuits. For example, smart authentication mechanism of the systems may be
phones, laptop computers and tablets, aircraft flight controls, bypassed.
the financial system, the power grid, automobile antilock Above hardware attacks may pertain to various devices
braking etc. These devices can be trusted only if the chips or systems like:
are free of hidden malicious circuits which may be inserted • Network systems
during the design or manufacturing process of the chips [4]. • Authentication tokens and systems
• Banking systems
Huawei introduced a mechanism for selection of the
• Surveillance systems
supplier through the list of 100 cyber-security requirements.
• Industrial control systems
The list of cyber security requirements basically covers 11
• Communication infrastructure devices
key areas: standards and processes, strategy governance and
Most of us do not bother about the risks of the supply chain,
control, human resources, laws and regulations, verification,
genuineness of supplier, trustiness of the manufacturing
research and development, manufacturing, third-party
process etc. But we generally mean cyber security only the
supplier management, issue, delivering services securely,
network security and data protection. It may be firewalls,
audit and defect and vulnerability resolution. At the time of
intrusion detection, secure and trained workforce, secure
supplier, organizations should explore the each area in
network design, social engineering etc.
details for detailed requirements [1, 2, 5, 6, 20].
But our assumption fails if one of the components is faulty
Physical supply chain management present numerous risks
in our network. If any component of the network is built to
during the phases of the chain. In cyber world also, supply
send the data outside of the network then general
chain plays an important role. If any cyber security
information assurance practices do not help too much. As
equipment is supplied through supply chain then there are
many companies get supply of the components from the
cyber security risks during the phases of supply chain. If any
contractors before the final assembly so, consumer may not
risk is detected after the delivery of the equipment then it is
be able to find who built the particular component of his/her
tough to detect the exact step of supply chain or sole
device. Authenticity of the supplied component is also
responsible person to the damage occurred due to delivery
doubtful if the contractor is not a reputed contractor or
of faulty equipment [7, 16, 17, 18].
he/she did not follow the manufacturing standards.
The attacking technology like virus inclusion in software or
Therefore, the efficient management of the supply chain of
hardware is on rise so, any hardware Trojans may be
the cyber security products is the necessity and this is also
inserted in any phase of the supply chain for the purpose of
the need for the cyber security program. If compromised
hacking [3]. There are various types of hardware attacks
components are prevented from entering in the network then
which includes the following-
it will improve the overall cyber security and reliability of
• Manufacturing backdoors may be created for
the product would be also increased [8, 9, 10, 11].
malware or other penetrative purposes. Backdoors
Cyber supply chain risks cannot be handled through
may be embedded in radio-frequency identification
Information Technology tool only. Cyber supply chain risks
(RFID) chips and memories.
touch sourcing of product, management of vendors,
• Unauthorized access of protected memory
transportation security, supply chain continuity and quality
© 2015-19, IJARCS All Rights Reserved 662
Om Pal et al, International Journal of Advanced Research in Computer Science, 8 (4), May-June 2017,662-666
and other functions across the organization and needs a (ix) What kind of access controls are in place.
coordinated effort to address the risk issues. Cyber security (x) How customer’s data is protected?
in supply chain is a multi dimensional problem which (xi) What are the encryption mechanism?
include management of supply chain, Quality and (xii) How much is the retention period for data?
production assurance standards, manufacturing process (xiii) What is the policy for data destruction when the
standards, IT problem etc[12, 13, 14, 15,21]. partnership is dissolved?
(xiv) Whether background checks are performed for
2. CYBER SECURITY PRACTICES AT SUPPLIER’S employees? If yes then how frequently?
END: (xv) What kind of security practices are followed.
(xvi) Whether there is proper cyber security check list for
Companies are using the questionnaire to evaluate the upstream and downstream suppliers? How is
security practice standards followed by suppliers. Using the adherence to check list?
appropriate set of questions, companies determine how (xvii) Whether proper security checks are performed for the
much security practices are risky of their supplier’s. distribution process?
Following are some questions which are being used for (xviii) What is the selection criteria for selecting the
making the questionnaire- distribution channels?
(i) Whether design process is documented? (xix) What is the mechanism to disposed off the counterfeit
(ii) Is the design process of software or hardware product component?
Repeatable? (xx) How does vendor assure the security of the process,
(iii) How vendor deal the existing and emerging product, service etc. throughout the product life
vulnerabilities? How vendor is capable to address cycle?
new vulnerabilities?
(iv) What kind of standards are being used by vendor to 3. SUPPLY CHAIN MANAGEMENT TIERS
manage and monitor manufacturing, assembling,
testing processes?. Supply chain management tiers describe the level of any
(v) How is code quality is tested? organization in terms of the familiarity of the organization
(vi) What techniques, procedures and approaches are with risk free SCM. Organizations may be categorized in
being used for protection and detection of malware. different levels according the risk free standards, rules,
(vii) How “tamper proofing” of products is done? What capability of countering the SCM risk, assessment of SCM
are methods for closing the backdoors? risk and capability of repeatability of the secure practice.
(viii) Whether all process are documented properly and SCM implementation tiers may be categorized in four
audition is conducted as per standards? categories-
Fig 1. SCM Tier Implementation
(i) Tier-I: In this tier, security related practices are not (ii) Tier-II: In this tier, at upper management level, the
well designed. In these type of organizations, Secure SCM practices have been approved.
secure SCM practices are partially followed. In However, Secure SCM practices are not being
case of any observed risk in SCM, it is counter followed within the organization at operational
down on ad-hoc basis. level. In these organizations, SCM risk assessment
is not repeatable.
© 2015-19, IJARCS All Rights Reserved 663
Om Pal et al, International Journal of Advanced Research in Computer Science, 8 (4), May-June 2017,662-666
(iii) Tier-III: In this tier, at upper management level,
the Secure SCM practices have been approved. 4. IMPORTANCE OF HAVING A SECURE SUPPLY
SCM risk assessment is also repeatable. These CHAIN MANAGEMENT LIFE CYCLE
organizations have well established agreements and
standardized communication with Government and Supply chain risk management is not just the delivery of the
other parties like supplier and consumers. products and services on time, but it is the delivery of the
(iv) Tier-IV: This is the highest level of SCM products and services with free of risks. A risk free and
implementation in any organization. At this level, efficient product life cycle is required which minimizes the
all policies, practices, rules, guidelines are well cyber security risks of the products and services. Cyber
formulated and are in practice. Organization has security risks may be defined as any abnormal activity like
well developed capability to counter any SCM risk malicious behavior tainted by malicious actors, or products,
in real time. This kind of organization, not only services may be counterfeited or contain counterfeit circuits,
follows risk free practices within the organization components etc. which may be used for illicit purpose.
but also it coordinates the secure SCM practices Only IT security system is not sufficient to secure critical
among other organizations, suppliers and information unless whole supply chain use secure cyber
consumers. security practices and standards.
Fig. 2: Cyber Security SCM Life Cycle
To manage the critical information in risk free manner, the parameters etc which should be considered and should
above proposed cyber security SCM life cycle may play an be expected from vendors. Huawei formulated the list
important role. If all steps of the Cyber Security SCM Life through asking the security related questions to buyers
Cycle are followed properly then a risk free SCM cycle may and vendor, and Huawei continuously assesses the
be achieved. standards and best practice to help buyers in analyzing
the cyber security capabilities of vendors while dealing
5. STRATEGIES, ROAD MAP AND SOLUTIONS TO with tenders.
RESOLVE THE THREATS OF CYBER SECURITY IN (ii) Huawei’s approach to tackle the supply chain risks
SUPPLY CHAIN- Huawei has also developed an ISO 28000 standard
supplier management system. This supplier
Global community as well as individual organizations management system is helpful in identifying and
should take the steps towards to reach an agreement on controlling the security risks during the end-to-end
principles, standards, laws, norms of conducts, best process from the point of incoming of the materials to
practices, and protocols for which the trust has to be build delivery of the product. Huawei selects and qualifies
up and continuously validated. Many organizations have suppliers based on their systems, process standards and
already started to tackle the issue of cyber security in SCM. products, choosing those that contribute towards the
Following are some important steps which have been quality and security to the products and services.
initiated by the organizations [21]- Huawei monitors and regularly checks the quality and
(i) Cyber Security Perspectives: 100 requirements efficiency of the qualified contractors and suppliers, and
formulated by Huawei Ltd- Huawei has formulated also checks the integrity of the materials provided by
the top 100 security-related requirements list. The third party, production and delivery process. Huawei
formulated list focuses on technology, security related evaluates the performance of each point of SCM and
© 2015-19, IJARCS All Rights Reserved 664
Om Pal et al, International Journal of Advanced Research in Computer Science, 8 (4), May-June 2017,662-666
establishes a traceable system throughout the supply of possible cyber security risks, process monitoring, product
chain of the products and services. evaluation, integrity check of third party products, history
(iii) NIST Framework is a tool that analyzes the possible check of network component suppliers etc is done properly.
risks and prepares an appropriate path towards a risk To address these issues, there is need of standard cyber
free environment for any organization. NIST security practice frameworks, cyber security guidelines in
Framework is a tool which analyzes the risks of a supply chain management to mitigate the cyber security
particular organization neutrally. It analyzes and risks in the supply chain of the network components. In this
applies the standards which are applicable in risk paper, the need of cyber security practice frameworks,
evaluation for that organization. In general, it lays out a Strategies, Road Map and possible solutions to resolve the
method of risk analysis framed by standards and best threats of Cyber security in supply chain are discussed and
practices, so any organization can use it. Using the analyzed. Each enterprise or business unit should practice
present standards and best practices of the organization, the appropriate supply chain frameworks and guidelines like
it analyzes the risks. It also provides guidance to NIST framework, O-TTPS, ISO 2800 (Supply chain security
organization and to help it to determine and implement Management). In addition of this, audit of Cyber SCM may
the best path forward by mapping the risk elements to be conducted at appropriate levels like branch level, regional
whatever standards are applicable to the requirement for level, and Country level etc. Questionnaire may be prepared
that sector or industry. by the expert committee for their employees to know the
(iv) Open Trusted Technology Provider Standard (O- security requirement at their functional level. Training and
TTPS)- O-TTPS has been recognized by ISO workshop may be conducted for employees to understand
(International Standards Organization) and International the available Frameworks, standards, best practices to
Electro technical Commission (IEC) as ISO/IEC reduce the risk in Cyber Security SCM.
20243:2015 recently. This tool address the risks related
to supply chain security, third-party providers, vendors 7. REFERENCES
and product integrity for any organization. O-TTPS
provides a set of predictive requirements and 1. [Link]
appropriate recommendations to follow the best 09/16/huawei_rfi_supply_chain.pdf
practices throughout the product lifecycle. 2. [Link]
(v) Initiatives taken by other Countries to tackle the introduces-cyber-security-top-100-requirements-for-
supply chain risks- [Link]
(a) Chinese Counter-terrorism Law (CTL), which took 3. [Link]
effect on January 1, 2016, outlines rules for internet and backdoors-and-electronic-component-qualification/
telecom enterprise to cooperate and support to 4. [Link]
government authorities in investigation of terrorist ware-cybersecurity
activities in China. Chinese Counter-terrorism Law also 5. [Link]
requires Internet Service Providers (ISPs) to implement security/[Link]#.WBxYsi197IU
the content monitoring system, and adopt the security 6. [Link]
measures as recommended by Government to prevent fSIG_29.09.15_DaveFrancis_Huawei.pdf
the dissemination of information which contains 7. Cyber-security risks in the supply chain, CERT-UK
extremist, terrorist and anti-national content. report 2015. ( [Link]
(b) Centre for the protection of national infrastructure content/uploads/2015/02/Cyber-security-risks-in-the-
(CPNI), UK Government- CPNI issues advisories to [Link])
organizations to implement a risk mitigation plan that 8. James J. Cebula Lisa R. Young (2010), A Taxonomy of
include the following: Comprehensive mapping of all Operational Cyber Security Risks, report of Carnegie
tiers of the upstream (supply of components from small Mellon University.
vendors to main vendor) and downstream (main vendor ([Link]
to consumer through distribution channel) supply chain 010_004_001_15200.pdf)
to the level of individual contracts which plays the role 9. David Inserra and Steven P. Bucci (2014), “Cyber
of risk-scorer in to the organization’s existing security Supply Chain Security: A Crucial Step Toward U.S.
risk assessment, assurance of suppliers, due diligence, Security, Prosperity, and Freedom in Cyberspace”
accreditation, appropriate and proportionate measures Backgrounder
to mitigate the risk, audit arrangements of the system ([Link]
and compliance of the security measures in the SCM pdf)
system. 10. [Link]
[Link]
6. CONCLUSION 11. [Link]
[Link]
It is seen that current practices to deal with cyber security 12. [Link]
risks in supply chain are not adequate. Any faulty assessment-management/
component in the network may be a serious cause of damage 13. CANSO Cyber Security and Risk Assessment Guide,
in terms of business loss, security breach, disclosing of June 2014
secret information etc. These kinds of cyber security risks ([Link]
may be minimized if proper inspection of the network yber%20Security%20and%20Risk%20Assessment%20G
components, monitoring of supply chain steps, assessment [Link])
© 2015-19, IJARCS All Rights Reserved 665
Om Pal et al, International Journal of Advanced Research in Computer Science, 8 (4), May-June 2017,662-666
14. [Link] 19. [Link]
management content/uploads/2016/03/[Link]
15. [Link] 20. [Link]
/20150622-is-your-supply-chain-safe-from-cyberattacks/ troduces%20Cyber%20Security%20Top%20100%20Re
16. [Link] quirements%20for%20Selecting%20Suppliers
ty 21. Framework for Improving Critical Infrastructure
17. [Link] Cybersecurity, National Institute of Standards and
tank/blog/article/why-cybersecurity-is-a-supply-chain- Technology(2017)
problem/ ([Link]
18. [Link] 01/30/draft-cybersecurity-framework-v1.1-with-
room/whitepapers/analyst/combatting-cyber-risks- [Link])
supply-chain-36252
© 2015-19, IJARCS All Rights Reserved 666
Copyright of International Journal of Advanced Research in Computer Science is the property
of International Journal of Advanced Research in Computer Science and its content may not
be copied or emailed to multiple sites or posted to a listserv without the copyright holder's
express written permission. However, users may print, download, or email articles for
individual use.