消除软件供应链管理的风险 (2020)

ID:64223

大小:0.08 MB

页数:2页

时间:2023-06-29

金币:10

上传者:亚森
Taking the Risk out of Software
Supply Chain Management
SPECIAL INTEREST EDITORIAL
Automating software life-cycle oversight
improves eciency, cuts costs.
BY HENRY S. KENYON
Supply chain management is
vitally important to running and
maintaining an organizations IT
systems, but like logistics systems,
it is not inherently sexy and has
historically drawn little attention
from the C suite. When it is carried
out, in many federal agencies it’s
traditionally a manual process
managed on spreadsheets. In recent
years new directives have mandated
that the Department of Defense
(DOD) and civilian agencies must
all begin monitoring this, especially
for cybersecurity considerations
within the Departments Risk
Management Framework (RMF).
Because of internal and external
cyber threat issues, many
department directors are paying
more attention to life-cycle
management from an acquisitions
perspective, says Frank Young,
director of Flexera Soware LLC’s
DOD business operations. But
while they now have to account for
this, in many cases directors and
chief information ocers (CIOs)
still don’t have any visibility into
how their department or agency
actually manages its soware from
acquisition to use to its retirement.
Speaking from the perspective of a
director in this situation, Young asks:
“How do I get an understanding
of what I purchased? And then if it
is deployed, was it over-deployed
or under-deployed? And are there
inherent risks that Im operating with
right now that Im not aware of?”
e risk level for manually
managing soware supply chains
isn’t acceptable any more, Young
says. ese cybersecurity-related
issues are now a pressing concern
in the DOD and the C suites of
companies doing business with
the government. He adds that not
knowing what is happening in
an organization prevents it from
conducting eective continuous
network monitoring or managing its
RMF requirements.
“If I dont know my soware life
cycle, I don’t know if I have soware
in my inventory that I can reuse. If
I dont understand it, I don’t know
whether I can take this to the cloud
or not,” Young says.
From the C suite, as long as networks
were running, corporate ocers and
agency directors weren’t as concerned
about the soware underpinning
their networks. However, new
requirements like RMF and health
records systems like the continuous
monitoring risk scoring system
have forced organizations and
their top leadership to be aware of
their soware life cycles and have a
standardized, repeatable process to
manage it, Young explains.
“It can bite you in the backside if you
dont have control over it, and cost can
really go out of control,” Young says.
GETTING IT RIGHT
WITH AUTOMATION
Automation is the key to helping
federal agencies tackle the
challenges of soware life-cycle
management to make their
operations more ecient.
One DOD agency contacted Flex-
era to help automate the part of its
soware life-cycle process where the
purchase information from its acquisi-
tion oces is merged with data from
a deployment perspective. is allows
the agency to have a process and a dis-
covery mechanism to see whats hap-
pening on its network, Young says.
For example, the system might allow
IT sta to know that while 1,000 cop-
ies of Tanium are deployed, it would
note that purchase orders say the
agency only paid for 900 and highlight
the cost for the additional copies. is
creates a risk picture for just one prod-
uct in the agency’s inventory which is
displayed on a user dashboard.
is allows an organizations ocers,
such as the CIO, to directly monitor
soware status from their dashboards
every day. Another important aspect
of this process for DOD agencies is
that it isn’t manual any more. Instead
it is a repeatable automated process
40 SIGNAL, MARCH 2020 | www.afcea.org/signal
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭