Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Nofsinger consultants met with the government officials and learned that they were concerned about managing the risks from attacks such as the 2 0 2
Nofsinger consultants met with the government officials and learned that they were concerned about managing the risks from attacks such as the Solar Winds attacks and longstanding trojansbackdoor attacks in network hardware eg Huawei routers and computer system components. The Solar Winds attack compromised the software update mechanisms for a widely used set of network management tools Korolov Supply chain attacks which compromise hardware components purchased from non US sources are also of concern.
Nofsinger consultants also analyzed the internal business processes involved in the engineering supply chain for client SifersGrayson. They have learned that, when a SifersGrayson engineer needs parts to build a robot or drone, the engineer will place an internal order from the companys parts stockroom. If the stockroom does not have the part immediately available, an employee will place an order with an approved vendor. These vendors are equipment resellers who purchase components from a number of manufacturers and suppliers. The company also makes purchases of components for some systems via eCommerce websites and has encountered supply chain issues as a result of using these systems to purchase common components such as CPU chips, memory chips, programmable control chips, power supplies, graphics cards, network interface cards, and mass storage devices. Some may be brandname components while other, less expensive products, are made by companies who are less well known. They also learned that SifersGrayson does not have a controlled process for testing software updates prior to the updates being installed on computer systems in the companys R&D labs.
Finally, the consultants learned through interviews that, at times, there are supply chain shortages which may result in a reseller substituting generic products for brand name products. The consultants informed SifersGrayson that such substitutions can increase risks associated with purchasing products from third parties whose reputations are unknown or less well established. The company responded that it has a quality assurance process which checks purchased parts for physical damage or lack of functionality. The consultants believe that this process can be improved to reduce the likelihood of an undetected supply chain attack eg malware loaded onto a USB or SSID mass storage device, programmable control chip, etc.
Your Task
Your task is to build upon the business analysis previously conducted by the Nofsinger consultants see overview section in this file You must research the problems of hardware and software supply chain attacks and then write a researchbased report for SifersGrayson executives which will provide them with information they can use to evaluate proposed solutions for addressing the identified supply chain risks. Use the authoritative sources provided below under Research to start your investigation into the issues. Then, follow the required outline See Write in this file to organize and write your report. You must paraphrase information from your authoritative sources and provide appropriate citations which identify your sources so that readers can fact check your work.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started