Can Internet of Things security be improved by the government procurement process?

From: American Enterprise Institute

***

Cybersecurity has traditionally focused on a limited number of end points, but the IoT is poised to change that as “the physical and virtual worlds combine at a large scale,” as one World Economic Forum report put it. IoT devices are often vulnerable to attack and exploitation because manufacturers want to appeal to consumers with devices that are affordable and simple to use, and manufacturers prioritize these attributes over security. As I have written previously, the “importance of securing IoT systems has been highlighted by cyberattacks that have used IoT objects as attack vectors to wreak havoc on internet transmissions.” In response, the security community has pushed for security by design, “the practice of building security into the basic design of devices that will be attached to a network rather than trying to patch designs after they’ve been connected to the network.”

The Federal Acquisition Supply Chain Security Act of 2018 introduced by Sens. Claire McCaskill (D-MO) and James Lankford (R-OK) in June is a good start to raise awareness about the need to improve the security of information technology attached to government networks. The legislation proposes to establish a cross-agency Federal Acquisition Security Council under the Office of Management and Budget. That council would then help executive agencies manage and mitigate supply-chain risk in the procurement of information technology. The bill requires the government to develop a strategy for supply-chain security and standards for measuring supply-chain risk, hoping to help agencies identify potentially risky information technology purchases.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *