Procurement risk in the cybersecurity industry

Assignment Help Business Economics
Reference no: EM131399712

Industry Profile Part 1: Acquisition & Procurement Risk in the Cybersecurity Industry

For this paper, you will investigate and then summarize key aspects of risk and risk management for acquisitions or procurements of cybersecurity products and services. The specific questions that your industry profile will address are:

  • What types of risks or vulnerabilities could be transferred from a supplier and/or imposed upon a purchaser of cybersecurity related products and/or services?
  • Are suppliers liable for harm or loss incurred by purchasers of cybersecurity products and services? (That is, does the risk transfer from seller to buyer?)
  • How can governance frameworks be used by both suppliers and purchasers of cybersecurity related products and services to mitigate risks?

First, you will research how operational risk during the manufacturing, development, or service delivery processes can affect the security posture (integrity) of products and services. You will then explore the problem of product liability and/or risk transference from supplier to purchaser as products or services are delivered, installed, and used. You will then examine the role that IT governance frameworks and standards can play in helping purchasers develop and implement risk mitigation strategies to compensate for potential risk transfer by suppliers. Once you have completed your research and analysis, you will summarize your research in a risk profile.

Research

  • Research risks and/or vulnerabilities which could be introduced into a buyer's organization and/or IT operations through acquisition or purchase of cybersecurity products or services. Some suggested resources are:
  • Hardware Security:
  • https://www.brookings.edu/~/media/research/files/papers/2011/5/hardware-cybersecurity/05_hardware_cybersecurity.pdf
  • https://resources.infosecinstitute.com/hardware-attacks-backdoors-and-electronic-component-qualification/
  • Software Security
  • https://buildsecurityin.us-cert.gov/
  • https://www.bsimm.com/
  • Data Center Security
  • https://www.datacenterjournal.com/managing-data-center-security/
  • Telecommunications Systems
  • https://www.pwc.com/gx/en/communications/publications/communications-review/assets/cyber-telecom-security.pdf
  • Identify five or more specific sources of operational risks, in a supplier's organization, which could adversely affect the security of cybersecurity products or services. In addition to using information you found under #1, consult the Software Engineering Institute's publication A Taxonomy of Operational Cyber Security Risks https://resources.sei.cmu.edu/asset_files/TechnicalNote/2010_004_001_15200.pdf
  • Research the issue of product liability with respect to cybersecurity products and services. What is the current legal environment? Some suggested sources are:
  • https://www.darkreading.com/vulnerabilities---threats/security-product-liability-protections-emerge/d/d-id/1320274
  • https://victorsheymov.com/2015/04/product-liability-the-unique-position-of-the-cybersecurity-industry/
  • https://www.travelers.com/prepare-prevent/protect-your-business/product-services-liability/product-liability-prevention.aspx
  • Research the role of IT Governance standards in helping organizations identify and manage risks arising from the purchase of IT related products and services. Begin by looking at the following:
  • COBIT®: AI5 Procure IT Resources
  • ITIL® Supplier Management SD 4
  • ISO/IEC 27002 Section 15: Supplier Relationship Management
  • 15.1 Establish security agreements with suppliers
  • 15.2 Manage supplier security and service delivery

Write

  • An introduction section which provides a brief overview of the cybersecurity industry as a whole. Why does this industry exist? (Hint: buyers want to procure or acquire cybersecurity related products and services). How does this industry benefit society? Address the sources of demand for cybersecurity products and services.  (You may reuse resources and/or narrative from your Case Study #3 assignment.)
  • An operationalrisks overview section in which you provide an overview of sources of operational risks which could affect suppliers of cybersecurity related products and services and, potentially, compromise the security of those products or services. Discuss the potential impact of such compromises upon buyers and the security of their organizations (risk transfer).
  • A product liability section in which you provide a summary of the current legal environment as it pertains to product liability in the cybersecurity industry. Discuss the potential impact upon buyers who suffer harm or loss as a result of purchasing, installing, and/or using cybersecurity products or services.
  • A governance frameworks & standards section in which you discuss the role that standards and governance processes should play in ensuring that acquisitions or purchases of cybersecurity products and services meet the buyer's organization's security requirements (risk mitigation). 
  • A summary and conclusions section in which you present a summary of your findings including the reasons why product liability (risk transfer) is a problem that must be addressed by both suppliers and purchasers of cybersecurity related products and services.

Your five to eight page paper is to be prepared using basic APA formatting (including title page and reference list) and submitted as an MS Word attachment to the Industry Profile Part 1: Acquisition & Procurement Risk entry in your assignments folder. See the sample paper and paper template provided in Course Resources > APA Resources for formatting examples. Consult the grading rubric for specific content and formatting requirements for this assignment.

Reference no: EM131399712

Questions Cloud

Compute the mean and variance and standard deviation : For a local charity, the donations in dollars received during the last month were 5, 10, 15, 20, 25, 50 having the frequencies 20, 30, 10, 40, 50, 5. Compute the mean, variance and standard deviation.
Major benefits for an organization to use ssds : Examine the major benefits for an organization to use SSDs. Analyze the major disadvantages and possible hazards that an organization should consider before adopting SSDs.
What is the purpose of risk score : What is the purpose of risk score? Do you see any reason to have it in your risk assessments?
Devise efficient search algorithm for an array of this type : Suppose that you have numerical data stored in a two-dimensional array, such as the one in Figure 18-9. The data in each row and in each column is sorted in increasing order.
Procurement risk in the cybersecurity industry : For this paper, you will investigate and then summarize key aspects of risk and risk management for acquisitions or procurements of cybersecurity products and services. The specific questions that your industry profile will address are:
Draw a histogram of given data : The data are also given in the musiccds dataset on the companion website.- Draw a stem-and-leaf plot of these data.- Draw a histogram of these data.- Characterize the shape of the data.
Questions based on the program : Answer the following questions based on the program given: unsigned int      inVal, out, k=0x0001, m=0x8000;
Is there relationship between whether or not hiv transmitted : For women who are HIV-positive when they get pregnant, is there a relationship between whether or not the HIV is transmitted to the infant and the length of time the woman had been infected before getting pregnant?
Define a java interface for your adt : Define a Java interface for your ADT. Then implement your interface as a class and test it. Use a text file of words to populate your data structure.

Reviews

Write a Review

Business Economics Questions & Answers

  Expected rate of return from this new computer software

Suppose that new computer software for accounting and analysis at a business has a useful life of only one year and costs $200,000 before it needs to be upgraded to a new version. The revenue generated by this software is expected to be $250,000. The..

  The various types of vehicles that can be used by clients

the various types of vehicles that can be used by clients to reduce the various kinds if taxation.

  Consulting firm of sands-gravel-concrete and waters

Rose is a Project Manager at the civil engineering consulting firm of Sands, Gravel, Concrete, and Waters, Inc. She has been collecting data on a project however not all the data is available. She has been able to find out that the 10th pillar requir..

  Changes in the federal funds interest rate

Changes in the federal funds interest rate often lead to similar changes in the prime interest rate

  Same quantity produced as the tax would have yielded

Where P is output price in $/bushel and Q is billions (1,000,000,000s) of bushels. Recall that this farm produces a negative externality of $1.5 per bushel. Let’s look at a using a regulation as compared to the tax. Graph the quota that yields the sa..

  Identify the principal and the agent

Each of the following situations involves moral hazard. In each case, identify the principal and the agent and explain why there is asymmetric information. How does the action described reduce the problem of moral hazard?

  What is the inevitable consequence of an active

With adaptive expectations, what is the inevitable consequence of an active, expansionary monetary policy in the short and long run?

  Explain how the determinant affects the demand for books

The determinants of demand and the demand for paperback books. For each of the following, state the determinant of demand that is changed, and explain how the determinant affects the demand for books.

  Quality-of-life measures be determined and measured

What economic factors are taken into account when measuring GDP? b. What makes GDP an effective measure of living standards? c. How might quality-of-life measures be determined and measured?

  In the competitive market for hamburgers

Assume that hotdogs and hamburgers are substitute goods. In the competitive market for hamburgers, there is an increase in the price of hotdogs (due to a decrease in the supply of hotdogs), and an increase in the cost of beef, an input used in produc..

  What was the real interest rate on your loan

You borrow $1,000 for one year at 5% interest to buy a couch. Although you did not anticipate any inflation, there is unexpected inflation of 5% over the life of the loan. What was the real interest rate on your loan? Explain how you gained from the ..

  Risk neutral insurance company offers fire insurance policy

A risk averse individual with a wealth of 156,000 and utility function U(x) = sqrt(x) is considering whether to purchase fire insurance for their home. The probability of a fire is 0.03. Repairing the damage from a fire costs 96,000. A risk neutral i..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd