Federal cyber chief: Supply chain security against foreign influence needs work
Full article794 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
But there aren't a lot of answers on how to do that, Grant Schneider says.
Although the U.S. government is working to prevent foreign telecommunications firms like Huawei from building 5G networks in the U.S. and abroad, there are still few answers on how to secure the government’s technology supply chain, according to federal Chief Information Security Officer Grant Schneider.
“Could [a company] come under the influence of a foreign adversary in any way shape or form? Is there quality where we need it to be? … How do we ensure their supply chain and the parts that they’re taking in and putting inside their box are actually the parts they’re expecting?” Schneider said at the Fortinet Security Summit, produced by FedScoop and StateScoop. “I don’t think we have an answer on what are the solutions to all those [questions.]”
The administration also isn’t clear yet on whether the government itself should be assessing which contractors are meeting requirements, or whether that assessment should be completed elsewhere, according to Schneider.
“As we look at our supply chain and we look at what our supply chain programs need to have, there’s going to be a variety of due diligence,” Schneider said. “And I think one of the things we’re looking at in the government is how much of that do we put on our providers.”
As far as whether the pendulum is swinging in the direction of government involvement or contractor control over supply chain decisions, Schneider does not think the government is in a position to presume suppliers and subcontractors are meeting supply chain requirements upfront.
“I’m probably not going to directly trust you’ve done them all,” Schneider told CyberScoop on the sidelines of the event.
It’s not just the tech that the government needs to worry about. When it comes to a recent case of two former Twitter employees who were charged with spying on Saudi dissidents on behalf of the Saudi Kingdom, Schneider indicated the private sector has a large role to play. When asked what the Trump administration should be doing to thwart tech companies being allegedly used for foreign espionage, Schneider pointed to Twitter.
“I think everyone has … a responsibility for their workforce and to know the actions that their workforce is taking and need[s] to have ways to be sure that they … have the proper controls in place,” Schneider said.
More Scoops
Supply chain challenges loom large in quantum race, White House official says
Brad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges.
Open-source security is posing challenges governments can’t easily solve
Critics call FCC router rule a ‘big swing’ that could create more supply chain uncertainty
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/grant-schneider-supply-chain-5g/