3.8 Proceedings Paper

Integrating Zero Trust in the cyber supply chain security

出版社

IEEE
DOI: 10.1109/WCNPS53648.2021.9626299

关键词

Zero Trust; Cyber Supply Chain; Software Bill of Materials; SBOM; DevSecOps; Gap analysis

资金

  1. Institutional Security Office of the Presidency of Brazil (GSI/PR)
  2. Brazilian Intelligence System (SisBIn)
  3. Brazilian Supreme Electoral Court (TSE)
  4. RedeGigaCandanga

向作者/读者索取更多资源

The use of a Zero Trust architecture in a cyber supply chain can enhance security by revising trust in all relationships and assuming the presence of internal threats. This study contributes to the improvement of cyber supply chain security by proposing security controls organization, providing a control checklist, and suggesting ways to visualize the results.
The cyber supply chain has been a target of sophisticated attacks. Vulnerabilities in components that were once considered secure due to perceived trusting relationships are being exploited. One way to reduce this type of cyber risk is through the use of a Zero Trust architecture. This type of approach revises trust in all relationships. It disregards the implicit trust in any component and is based on the premise of the existence of internal threats to the corporate network. The present work proposes to integrate a Zero Trust architecture in a cyber supply chain. The main contribution of this study is to propose an organization of security controls for a cyber supply chain in domains, enabling improvements in the security of the cyber supply chain by applying the principles of a Zero Trust architecture. The study also provides a checklist of controls that allows a gap analysis and suggests some ways of visualizing this result.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据