Please use this identifier to cite or link to this item: https://dair.nps.edu/handle/123456789/5432
Title: An Assurance Educated Workforce Is Critical to Addressing Software and Supply Chain Acquisition Lifecycle Risks
Authors: Carol Woody
Keywords: software
supply chain risk management
acquisition lifecycle
cybersecurity
workforce education
Issue Date: 13-May-2025
Publisher: Acquisition Research Program
Citation: APA
Series/Report no.: Acquisition Management;SYM-AM-25-421
Abstract: Today’s systems are software-intensive and complex, with a growing reliance on third-party technology. Through reuse, systems can be assembled faster with less development cost. Traditionally, systems were hardware-based, and operational risks were primarily linked to reliability. Now systems are largely software-based, which does not wear out like hardware, and the critical risks are different. All software contains vulnerabilities that are hard enough to manage directly. Inheritance through the supply chain increases the management challenges and magnifies the risk of a potential compromise. Attacks on the software supply chain are increasingly frequent and devastating. Software risk management capabilities are brought in too late, if at all, to identify and address software risks that can appear throughout the lifecycle. Extensive compliance rules have been put in place for federal acquisitions to address software and supply chain risk, but there is a noticeable gap in the current acquisition and engineering workforce’s knowledge and skills needed to address the rules effectively. Expanding the knowledge of decision-makers and participants in system acquisition, engineering, and integration are critical activities that are necessary to address the growing software risk.
Description: SYM Paper
URI: https://dair.nps.edu/handle/123456789/5432
Appears in Collections:Annual Acquisition Research Symposium Proceedings & Presentations

Files in This Item:
File Description SizeFormat 
SYM-AM-25-421.pdfSYM Paper589.96 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.