2021-12-31-兰德-软件供应链风险披露(英)_12页_156kb
报告摘要
Summary of "Disclosure of Software Supply Chain Risks"
Core Content
The document outlines the growing concern of software supply chain risks in the context of cybersecurity and highlights the SEC's current approach to managing these risks through disclosure requirements. It argues that while the SEC has made strides in addressing cybersecurity in general, it has not yet specifically addressed software supply chain risks, which are increasingly significant due to the complexity and interdependence of modern software systems.
Main Viewpoints
- The reliance on software for critical business operations has grown significantly over the decades, making software vulnerabilities a major threat.
- Malicious or accidental software failures can lead to billions in losses, data breaches, and government records compromise.
- The use of third-party and open-source software has increased, leading to greater exposure to supply chain risks due to the lack of oversight.
- The SEC has not yet developed specific rules for software supply chain risk disclosure, despite its broader cybersecurity initiatives.
Key Information
The Nature of Software Supply Chain Risks
- Modern software applications are built using third-party and open-source components, developed by thousands of contributors globally.
- This decentralized and complex ecosystem increases the risk of compromise and makes oversight difficult.
- Examples of major vulnerabilities include:
- Heartbleed (2014)
- Log4j (2021)
- SolarWinds (2019)
SEC's Cybersecurity Disclosures
- In 2011, the SEC issued guidance on data breach disclosure.
- In 2018, it updated its guidance to include cybersecurity risk management and incident disclosure.
- In 2022, it proposed new rules for cybersecurity risk management, strategy, governance, and incident disclosure.
- The SEC does not currently require specific disclosure of software supply chain risks, even though they are a subset of cybersecurity threats.
Y2K as a Precedent
- The Y2K issue served as an early example of software supply chain risk, where date handling errors in software could cause system failures.
- The SEC required disclosure of Y2K risks, including:
- Readiness status
- Costs to address the issue
- Risks involved
- Contingency plans
- The SEC also emphasized the importance of third-party relationships and contingency planning for those who could cause material harm if not compliant.
Proposed Disclosure Guidelines
- The document suggests that the SEC should consider specific disclosure requirements for software supply chain risks, based on the Y2K model.
- Proposed elements include:
- Disclosure of processes for managing software supply chain risks.
- Scope of risk management efforts, identifying which services are material.
- Contingency plans in case of supply chain disruptions.
- Disclosure of software dependencies, including SBOMs (Software Bill of Materials).
- Disclosure of third-party software usage, especially critical software as defined by NIST.
Role of NIST
- NIST has developed guidance on software supply chain security and critical software categories.
- The SBOM is a formal record of software components and their supply chain relationships, which can help in identifying vulnerabilities and managing risks.
Structure of the Document
Introduction
- The increasing reliance on software in critical services has led to greater exposure to cyber risks.
- Examples of major cyber incidents are provided to illustrate the magnitude of the problem.
Recognition of Software Supply Chain Risks
- The importance of open-source software in modern systems is acknowledged.
- Executive Order 14028 (2021) recognizes the need for software supply chain security.
SEC's Role in Cyber Risk Disclosure
- The SEC has issued various guidelines related to cybersecurity and data breaches.
- These guidelines do not specifically address software supply chain risks.
Y2K Disclosure as a Model
- The Y2K disclosure framework can be used as a model for software supply chain risk disclosure.
- It includes readiness status, costs, risks, and contingency plans.
- Third-party dependencies are also a key part of the Y2K disclosure requirements.
Proposed Disclosure Elements
- The SEC could require companies to:
- Describe their risk management processes.
- Outline the scope of their efforts.
- Disclose the use of critical software.
- Provide information on third-party software vendors.
- Include SBOMs to improve transparency and risk management.
Conclusion
- The document concludes that increased disclosure of software supply chain risks will help investors assess the cybersecurity posture of organizations.
- It urges the SEC to adopt specific disclosure rules to address this underestimated risk.
References
- Executive Order 14028 – Defines critical software and supply chain security.
- NIST – Provides guidance and definitions for software supply chain management.
- SEC Guidance – Includes Y2K disclosure requirements and cybersecurity rules.
- Veracode and Core Infrastructure Initiative – Highlight the prevalence of open-source software and complex dependencies.
Authors
- Sasha Romanosky – Senior policy researcher at RAND Corporation, with a focus on cybersecurity and national security.
- Jonathan W. Welburn – Researcher at RAND Corporation, specializing in operations research and computational economics.
About the Perspective
- The document is part of a RAND Corporation initiative, supported by the Institute of Civil Justice and the Kenneth R. Feinberg Center for Catastrophic Risk Management and Compensation.
- The goal is to improve transparency and risk management in the software supply chain for investors and organizations.
Acknowledgments
- The authors thank reviewers and supporting institutions for their guidance and assistance.
Institute for Civil Justice
- The RAND Institute for Civil Justice (ICJ) focuses on improving the civil justice system through nonpartisan research.
- It addresses issues like liability, compensation, regulation, and risk management.
Research Integrity
- The RAND Corporation is committed to quality, objectivity, and integrity in its research.
- It ensures rigorous and unbiased analysis through peer review and transparent processes.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载