TechKnowSurge
NIST CSF GV.SC-01 NIST 800-53 SR-2 ISC2 CISSP 1.11 CompTIA Security+ 5.3 NIST NICE K0834 NIST NICE K0653 NIST CSF GV.SC-06 NIST 800-53 SR-5
VideoSecurityFree

Supply Chain Management

Supply chain security involves analyzing every vendor and component in the chain of products and services that support an organization's operations. Understanding these dependencies helps identify risks ranging from component shortages to security vulnerabilities introduced by third-party suppliers.

Complete this video to capture a CTF flag worth 1 point.

About this video

Supply chain management is a critical discipline in both business operations and cybersecurity, encompassing every vendor, supplier, and component involved in delivering a product or service. When an organization sources materials or technology from outside vendors, and those vendors source from their own suppliers, a layered chain of dependencies forms — one that can extend far beyond what is immediately visible. Each link in that chain represents a potential point of failure or compromise, whether through component shortages, inconsistent product quality, or deliberate security threats introduced at the supplier level. The laptop market offers a clear illustration of how complex and far-reaching these chains can become. A single device may incorporate processors from one vendor, batteries from another, and firmware or software components from several others. When a shared battery supplier shipped a defective batch years ago, the impact was felt across multiple major brands simultaneously — a direct consequence of converging supply chains. More recently, a global chip shortage constrained laptop production across the industry and drove up consumer prices, demonstrating how a disruption at one node can cascade through an entire market. For organizations deploying technology at scale, supply chain visibility becomes a security and operational priority. Business-grade products typically carry higher price points in part because they come with greater assurance about component sourcing, consistency, and security standards — guarantees that matter far more when deploying thousands of devices than when purchasing a single consumer machine. Assessing supply chain risk means evaluating not just hardware components but also software dependencies, including third-party code libraries, modules, packages, and container images, all of which can introduce vulnerabilities if left unexamined.

What you'll learn

What's covered

Supply Chain Management

Aligned to

NIST CSF
GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders.
GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships.
NIST 800-53
SR-2 Supply Chain Risk Management Plan
SR-5 Acquisition Strategies, Tools, and Methods
ISC2 CISSP
1.11 Apply Supply Chain Risk Management (SCRM) concepts
CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management.
NIST NICE
K0834 Knowledge of technology procurement principles and practices
K0653 Knowledge of cybersecurity practices in the acquisition process

Key terms

Supply Chain Risk Management
SCRM
Supply Chain Risk Management is the process of identifying, assessing, and mitigating risks arising from the use of third-party hardware, software, and services throughout the supply chain, addressing threats such as counterfeit components and malicious code insertion.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Third-Party Dependency
An external vendor, supplier, or component—such as hardware, software libraries, or container images—that an organization relies on to deliver its products or services.
Supply Chain Visibility
The degree to which an organization can identify and evaluate the components, vendors, and processes that make up its supply chain for security and quality assurance purposes.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.

Topics

Supply Chain Security Third Party Risk Vendor Management Risk Management Procurement Security Cybersecurity

Transcript

When I'm delivering services and products to my clients, I'm also looking at the vendors that supply products and services to me. This develops what's called the supply chain, and we need to manage the whole supply chain, and we need to look at the supply chain of our vendors.

What the Supply Chain Is

Let's say I'm a company that creates a product and I'm selling that product to my clients. There's material that goes into creating that product, and I'm getting that from other vendors, and they're getting material from other vendors. So what happens is we create this chain of material that goes into creating the product that I'm going to sell to my clients. We call that the supply chain, and it's something that we have to analyze from a security perspective to make sure we're doing security correctly.

A Laptop Supply Chain

Let's take a look at a laptop supply chain just for some context, and let's look at a specific brand. Let's say this is a Dell computer. Dell purchases a lot of products from other different entities. For instance, they purchase their chips and their motherboards and all their processing power and their Wi-Fi from other companies. If you look at a Dell laptop you can see where it says Intel in there, or AMD, or wherever they're purchasing it from. You can see the different components from all of these other companies.

One of the things that they'll purchase from other companies is batteries. They'll purchase batteries from other companies to put in their laptops. I know this because at one point in time there was a bad batch of batteries that went out and it affected a lot of Dells and a lot of Macs and a lot of Asus, a lot of different brands it affected, because they were all buying from some of the same suppliers.

So we see a supplier of the battery. Well, they have purchased the products to make these batteries, they purchased from other people. There are chemicals that go into these batteries, and the company that makes the battery is not necessarily the company that goes and mines all of these chemicals that go into the batteries. So we see this whole supply chain form, and they can get very large.

Supply Chain Vulnerabilities

There can be a lot of vulnerabilities to these supply chains. There could be shortages, there could be changes in products, there could be security issues with it. For instance, in this case right here, the battery, there could be chemical shortages, which creates a shortage in batteries, which creates a shortage in the amount of laptops. We saw this recently with chips: there was a shortage on chips, which caused all sorts of problems with how many laptops were on the market, and that drove up the price of these laptops.

So what we need to do is a supply chain analysis, and figure out what this supply chain is, so that we make sure we're buying the right products.

Business Versus Consumer Lines

It's one of the reasons why there are really expensive laptops that are business-line laptops and really inexpensive lines of laptops that are more for the consumer. A consumer is usually buying one laptop, and it's not a big deal if the products and services that go into delivering that product vary a little bit, because they're just buying the one machine. But it becomes more critical when you are a business and you've got thousands of machines. If you have thousands of different machines, then that can be problematic.

So by buying the business level laptops, you're guaranteed a little more with what goes into that laptop, and making sure that there's an element of security involved, and that the product that's going into it remains relatively consistent. It's one of the reasons why some of these business-line products actually cost more than their consumer level counterpart.

Visibility and Third-Party Dependencies

One of the issues that creeps in with supply chain is the visibility. We don't always get a really good sense of what all goes into this laptop, nor do we have a limitless number of resources to research all of that. So what we're going to have to do is make a decision on: do we trust the company that's providing this laptop, and can we get some visibility into their supply chain to understand if they are providing a good product for us?

Some of the third party dependencies might be different hardware or software. Maybe it's different code libraries or different code that goes into it, different modules, different packages, maybe different container images. So there's a lot of things that will go into these products and services.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →