In April 2018, the Office of the Director of National Intelligence’s National Counterintelligence and Security Center (NCSC), the Cybersecurity & Infrastructure Security Agency, and the Department of Defense’s Center for the Development of Security Excellence launched an awareness campaign highlighting growing threats to supply chains. This April marks the fourth annual National Supply Chain Integrity Month with numerous government and industry partners focusing on escalating concerns from supply chain threats. During each year of the campaign, the NCSC’s summarized examples of successful attacks on supply chain integrity have illustrated the real and present risks. However, the campaign is not about awareness: it is a call to action.
The term “supply chain” has become a punching bag since last year for international media outlets, social media, and the virtual water cooler. Disruptions to numerous global supply chains have affected the daily lives of billions of people: from toilet paper to microelectronic chip shortages; from SolarWinds to ransomware and other cyberattacks; from the cargo ship Ever Given in the Suez Canal to challenges in developing, making, delivering, and administering COVID-19 vaccinations efficiently and effectively; and from extreme weather events to geopolitical friction across the globe.
Three years before the inaugural National Supply Chain Integrity Month, the Computer Security Division of the National Institute of Standards and Technology (NIST) published Special Publication 800-161, “Supply Chain Risk Management Practices for Federal Information Systems and Organizations.” While its target audience was information systems practitioners, its thorough approach to addressing supply chain risk management (SCRM) offers a template for organizations’ entire SCRM programs, not just cybersecurity SCRM (C-SCRM).
The NIST team defined four pillars of C-SCRM—security, integrity, resilience, and quality—and describe the overlap of the pillars. These pillars (or categories) assist with finding, assessing, prioritizing, and mitigating risks to the supply chain from different perspectives. For added comprehensiveness, adding a fifth pillar for responsibility would consider social and environmental responsibility. This new pillar encourages organizations to assess the likelihood and effect of supply chain disruptions. These disturbances range from global human rights concerns to local labor issues and environmental sustainability as well as the long-term influences from the climate and our ecosystem. The overlap between these pillars is critical: you cannot have a comprehensive SCRM program to adequately protect your organization’s mission without accounting for all practical perspectives or categories of risk.
Previous Supply Chain Integrity Months focused on adversarial or intentional threats, often from nation-states. Last year’s events highlighted the need to find and mitigate all sources of supply chain disruptions appropriately. Supply chain integrity is critical to the national defense mission. It is well worth the energy and effort to raise awareness about it. Every supply chain disruption caused by a natural disaster, negligence, poor quality, etc., exposes a list of vulnerabilities that can be targeted and exploited by a well-resourced adversary. However, integrity alone is not enough, nor can you limit SCRM to one month a year.
Not many (if any) organizations appropriately assessed the likelihood and effects of a pandemic (or the other disruptions in the headlines), let alone proactively mitigated the associated risks to ensure against adverse effects to the mission due to supply chain failures and disruptions. Lessons learned need to be turned into action: your SCRM program needs to mature—now. LMI’s experience standing up SCRM programs highlights three critical steps for the maturation process.
- Build the appropriate governance and structure for an SCRM program with a designated executive champion. While the program should be tailored to every organization based on mission and risk appetite, SCRM needs to be an integral part of every organization’s enterprise risk program.
- Comprehensively assess the entire risk landscape to address all threats, consequences, and likelihood of attacks, disruptions, and vulnerabilities. All government organizations need to pay particular attention to supply chain integrity threats but must not overlook or underestimate the mission effect of other threat categories.
- Illuminate who is in your supply chain and how they influence you and your mission. Many organizations exclusively review their key first-tier suppliers. To mature appropriately, organizations must understand their end-to-end supply chain, especially considering the global nature of supply chains and the associated geopolitical considerations.
With these essential building blocks, your organization can make informed, proactive, risk-based decisions to ensure better preparation for the next supply chain disruption. While it is great to bring more awareness to supply chain integrity during April, improving SCRM will take a coordinated, long-term effort to move from reactive to proactive risk management.
Jon AmisPrincipal, Supply Chain Solutions Meet Jon
Jon AmisPrincipal, Supply Chain Solutions
Jon offers LMI’s customers practical industry expertise and thought leadership in supply chain risk management (SCRM) and cyber SCRM. His contributions build on a foundation of over 30 years of experience and leadership in manufacturing, distribution, and logistics.
Supply Chain Resiliency
We combine our supply chain and government operations experience to deliver practical solutions that reduce and manage your risk and achieve a resilient supply chain that meets your organizational goals.