ICT Supply Chain Integrity: Principles for Governmental and Corporate Policies
Core Content
This document, ICT Supply Chain Integrity: Principles for Governmental and Corporate Policies by Ariel E. Levite, addresses the growing concerns over the security and integrity of information and communication technology (ICT) and operational technology (OT) supply chains. It outlines the challenges posed by both inadvertent vulnerabilities and deliberate interventions by state and corporate actors, emphasizing the need for a balanced, cooperative approach to safeguarding the global digital ecosystem.
Main Points
- Global Importance of ICT/OT: ICT/OT products and services are essential for governments, industries, and the public. Their performance relies on secure and reliable supply chains.
- Declining Trust: Concerns over supply chain vulnerabilities and intentional backdoor interventions are undermining trust in ICT/OT. These issues are often exacerbated by political and commercial motivations.
- Interventions by Governments and Corporations: Both entities may engage in interventions for national security, law enforcement, or commercial reasons. These include undermining encryption, inserting backdoors, and building undisclosed features.
- Consequences of Interventions: The effects can range from data breaches and operational disruptions to geopolitical tensions and economic instability. Examples include the Meltdown and Spectre vulnerabilities, NotPetya attacks, and alleged cyber operations by various countries.
- Need for a Normative Framework: The paper proposes a framework of four key obligations—trust, accountability, transparency, and receptivity—to enhance supply chain integrity and mitigate risks.
Key Governmental and Corporate Obligations
Trust
| Governments |
Corporations |
| Prohibit systemic supply chain interventions |
Do no harm—refrain from creating or inserting vulnerabilities |
| Limit the scope, scale, and negative consequences of interventions |
Apply the highest practical level of security and integrity throughout the product lifecycle |
Accountability
| Governments |
Corporations |
| Establish internal processes for informed, risk-based decisions on supply chain interventions |
Quickly address known vulnerabilities and abuse |
| Pair interventions with plans to mitigate adverse consequences |
Consistently assess implications of quality and safety concerns |
Transparency
| Governments |
Corporations |
| Publish policies and procedures for handling supply chain security concerns |
Make public the core principles and practices of product security |
| Lay out clear criteria for vendor accreditation and product certification |
Allow reasonable scrutiny by customers and authorities |
| Inform foreign customers of conflicting supplier directions |
Ensure compliance with relevant laws and regulations |
Receptivity
| Governments |
Corporations |
| Establish channels with corporations and stakeholders to discuss supply chain integrity |
Respond expeditiously to law enforcement and security concerns |
Implementation Mechanisms and Next Steps
Platforms for Anchoring the Obligations
- Governmental: Unilateral or collective declarations, formal trade arrangements, and international documents (e.g., G7/G20 communiques, GGE, OEWG, WTO, ITU, OECD)
- Corporate: Participation in multi-stakeholder processes, CSR/ESG initiatives, and technical standards-setting organizations (e.g., NIST, ISO, IEC)
Additional Incentives for Adherence
- Governmental: Deny access to contracts or markets for non-compliant entities
- Corporate: Create reputational benefits for adherence, use due diligence procedures to encourage compliance
Mechanisms for Verifying Compliance
- Governmental: Leverage best practices for quality assurance and traceability to aid investigations
- Corporate: Invite government support for vulnerability analysis, establish independent international mechanisms for technical diagnosis
Next Steps
- Governmental: Outreach to governments and corporations to seek buy-in for core principles
- Corporate: Develop mechanisms for verification and operationalization of standards, explore options for CSR/ESG initiatives
Challenges and Considerations
- Persistent Risks: Despite efforts, state and corporate interventions will likely continue due to strategic, commercial, and security incentives.
- Technological and Legal Complexity: Interventions can be difficult to detect and may be legally justified in some jurisdictions.
- Impact on Global Economy and Innovation: Balkanization of supply chains and politicization of security concerns can hinder innovation and economic openness.
Conclusion
The paper advocates for a coordinated, multi-faceted approach to supply chain integrity that involves both governmental and corporate entities. It emphasizes the importance of balancing national security interests with the need to maintain trust, transparency, and cooperation in the global digital economy. The proposed framework aims to restore confidence in ICT/OT supply chains and ensure that they remain secure and reliable for all stakeholders.